Our Services

Get 15% Discount on your First Order

[rank_math_breadcrumb]

Wk4_415

Need help with a question

Due 9/1/2024

The health care organization IT staff has notified the CISO that one of the new NewTab iPads® has been misplaced, though it is not known if it was lost or stolen. The NewTab information system does not have a mobile device management capability that could track and wipe the device before the sensitive data on the device can be compromised.

Refer to the
NewTab Project Profile as you complete Parts A and B below.

Part A: Create an Incident Response Plan

Create a 4- to 4.5-page incident response plan (IRP) specifically for the NewTab missing iPad incident, based on the 4 major components of incident response. Include the following in the IRP:

· Introduction

· Bulleted list of key stakeholders on the health care organization’s Response Team for the NewTab information system

· Bulleted list of compliance/regulatory requirements with respect to the health care organization and NewTab information system

· Component 1: Discovery, including the following:

· Events that should be logged and monitored with respect to the NewTab information system

· How the lost or stolen iPad® incident was discovered and reported

· Component 2: Escalation, including the following:

· Bulleted list of what triggers an event into an incident with respect to the NewTab information system

· Bulleted list of the severity of impact

· Summary of the steps for escalating the NewTab incident

· Component 3: Response, including the following:

· Summary of the planned response for the NewTab incident, including the following:

· Response to the notification of the NewTab incident

· Notification of applicable members on the Response Team

· Summary of the response

· Component 4: Reporting and Lessons Learned, including the following:

· Summary of who participates in the lessons learned for the NewTab information system incident

Part B: Create a Penetration Testing Agreement

Based on the recent incident with the NewTab information system, the CISO has been tasked with hiring a vendor to conduct independent penetration testing on the NewTab information system.

A penetration test agreement is very important to ensuring that both parties, the penetration tester and the client (your company), understand the purpose and scope of the penetration test.

 

Create a 2- to 3-page penetration testing agreement for the NewTab information system with the major sections listed below. Include the purpose and examples for each section.

· Scope for testing of the NewTab information system, including the following:

· Compliance/regulatory requirements

· Internal or external testing or both

· Technical testing

· Physical security testing

· Threat identification (i.e., who and what are the threats to the NewTab information system)

· Legal issues that must be considered

· Components to be tested, including the following:

· Gathering publicly available information

· Network scanning

· System/application scanning

· Privilege escalation

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

GitHub

see attachment for details DAT 260 Module Eight Journal Guidelines and Rubric Overview As you have learned in the module resources, GitHub is more than just a place to store code. It is a dynamic community of practice and a living portfolio of your coding skills. In this journal entry,

Blockchain app programming

i have the template provided and you will have to use the term project presentation to complete it.  Secure-Trade CIS-5730 – Blockchain Applications TERM PROJECT PRESENTATION The money is stored in a digital wallet in the blockchain until two parties pass release or refund (Safe, 2026). The same agreement promotes

HIMS 655 ASS8

Watch the YouTube Video MEDICAL CODING ICD-10-CM GUIDELINES LESSON – 1.B – Coder explanation and examples for 2021 Review the ICD-10-CM Official Guidelines for Coding and Reporting at   and in your assignment respond to the following questions: Who is responsible for framing these Guidelines? Why are these guidelines necessary for

HIMS 645 ASS8

Using Internet resources, search  three national and three international healthcare organizations that maintain databases and use the information based on the processed data from these databases in their decision-making process. Briefly describe the organizations and types of data contained in their databases (make sure to remember quality of data points and

W8: Topic 1 – Course Wrap-Up

 Pick one topic from this class that most interested you. State the topic and your reasons for the choice. ii. You need to respond to at least 2 students.  This is part of your grade to be active in the threads and responding to students.   NB: THIS IS THE TOPIC

Big Data Tools and Emerging Technologies

please see attachment  4 [ Note: To complete this template, replace the bracketed text with your own content. Remove this note before you submit your project.] Big Data Tools and Emerging Technologies Paper [Your Name] DAT 260: Emerging Technologies and Big Data [Your Instructor’s Name] [Date—for example, May 1, 2021]

HIMS 655 ASS7

Mapping between SNOMED-CT and ICD-10-CM Note: For completing this assignment, use of the I-MAGIC tool (Interactive Map-Assisted Generation of ICD Codes) is required. To access the I-MAGIC tool, click on the following  ) Problems and diagnoses can be recorded in SNOMED CT in the EHR, while the cross-mappings to ICD-10-CM can

HIMS 645 ASS7

Four types of databases are Relational, Network, Hierarchical, and Object-Oriented. What are their salient features (a table format is acceptable)? Assess their usability for healthcare facilities that generated numerical, text, and images data citing reasons for your choice.  Two most commonly used databases in healthcare organizations are Relational and Object-Oriented (O-O). Both employ respective

MS ACCESS

Need to do a Microsoft Access document for my work.  2 Consideration of MS Access Database Development on Healthcare. Name Instructor School Date Consideration of MS Access Database Development on Healthcare. Introduction The task entailed developing a Microsoft access database of a small healthcare facility, which has just abandoned the

Effective security programs

Organizational policies define the direction for an organization and contribute to its overall security culture by setting the tone on what is and is not acceptable. 

The Equifax Data Breach

Briefly explain what the Equifax data breach was, why it happened, and why it was important. You should mention that Equifax failed to protect personal data, discuss the ethical and security issues involved, and explain what companies can learn from the incident. Please see attached documents.