PROJECT PART 1 TASK 1 RISK MANAGEMENT PLAN
2. OUTLINE OF THE PLAN The outline of the risk management plan covers all the steps involved in developing the plan for an organization. Step1 Identification of Risks This step involves identifying all the risks that may arise from the organizational processes. There are several risks identified. Few important risks are stated below: A. Loss of data due to hardware being removed. B. Loss of data due to stolen devices. C. Loss of customers due to production outages. D. Internet threats E. Insider threats F. Changes in regulatory landscape. Step2 Evaluating of the Risks Evaluation of the risks involves describing each risk and the consequences to the organization if the risk occurs. The impacts of each of the risks identified are given below: A. Loss of data due to hardware being removed IMPACT: The loss of data results in devastating effects like all the information data of the Health Network Inc. can be lost like all the details of the doctors, pateints and their payments, employees and their salaries, the plans and all the data that is stored on the hard drives. B. Loss of data due to stolen devices IMPACT : The results of loss of data due to stolen devices is even more harmful in addition to all the effects from the loss of data due to removal of hardware. Because when the devices are stolen , it means all the data is now in the wrong hands and in may result in misuse of the data. C. Loss of customers due to production outages IMPACT : The production outages such as natural disasters, change management, unstable software etc. results in customer loss which ultimately results in huge revenue losses, damage to Health Network Inc.’s reputation, loss of clients etc. D.Internet threats IMPACT: Because Health Network Inc. Operates in three production data centers which are located at different geographic locations, it requires confidential data to be transmitted over the internet. Also the customers and doctors need to access the internet to avail the services. So this can lead to many harmful threats to the company such as virus attacks, data breach, leakage of important details like credit card details. E.Insider threats IMPACT : An insider is person who has the access permission to the organization’s protected assets. The insider are the employees who can intentionally or unintentionally harm the data of Health Network Inc. An insider is capable of leaking 5 sensitive information of any patients medical reports, credit card details or doctors’ information. F.Changes in regulatory landscape. IMPACT : The change of laws or regulations made by the government can increase the costs of complying with it , change in the fees that can be charged by patients. Step3 Ranking of Risks After determining the consequences of the risks on the organization , the risks are prioritized based on its probability of occurrence and its magnitude. The risks are ranked as: 6.Internet threats 5. Loss of customers due to production outages 4. loss of data due to stolen devices 3. Insider threats 2. Loss of data due to hardware being removed 1.Changes in regulatory landscape RANK RISK PROBABILITY MAGNITUDE 6 Internet threats Once in 6 months High 5 Loss of customers due to production outages Once in 2 years Very high 4 loss of data due to stolen devices Once in a year Medium 3 Insider threats Once in 2 years Medium 2 Loss of data due to hardware being removed Once in 3 years Low 1 Changes in regulatory landscape Once in 2 years Low Step4 Ways to reduce the Risks After prioritization of the risks , the risks are detected and treated by providing certain procedures. Given are the ways to reduce the risks of Health Network Inc.: A. Loss of data due to hardware being removed: Proper backup should be done regularly and stored on the cloud. Before replacing any hardware it should be thoroughly checked. B. Loss of data due to stolen devices: Proper backup of data must be done on a regular basis. And all the devices must be password protected and encrypted. C. Loss of customers due to production outages : We need to be ready with a decent disaster management plan incase of any natural disaster. We have to use both offsite data backup and third party vendor data backup. The software should be updated frequently. The employees must be trained well to handle the situations like change management with an ease. D. Internet threats: Usage of password protected encrypted networks, using routers secured with N-security, and links and attachments should only be opened if they are
Written for
- Institution
-
University Of The Cumberlands
- Course
-
RISK 533
Document information
- Uploaded on
- November 30, 2022
- Number of pages
- 11
- Written in
- 2022/2023
- Type
- OTHER
- Person
- Unknown