Question

In: Computer Science

Policy Drivers The purpose of this assignment is to practice and demonstrate your ability to interpret...

Policy Drivers

The purpose of this assignment is to practice and demonstrate your ability to interpret detailed policy. We have chosen for you to take a look at two of the most well known policies; in real life, you will have government polices such as these as well as enterprise specific policies or regulations. As you build information systems, it is key to early on in the process to identify all relevant policy drivers and understand them.

In the module, we discussed how an organization's policies and regulations for data governance influence the nature and structure of IT/IS systems. For your assignment, research either HIPAA (for health care) or Sarbanes-Oxley (for financial data). In 1 page, describe at least two of the policies you find and explain how an IT/IS system would need to accommodate.

Solutions

Expert Solution

HIPAA Policies
1)To protect Health information:
HIPPA protects following types of health information.

a)Personal information:
such as name, address, contact number,email, social security
number,photograph.
b)Medical information:
such as medical history,medical certificates,medical prescription
and so on.
c)Technical information:
IP address,URLs,biometric details such as fingerprints.


2)Administrative Safeguard:
Administration is supposed to develop some security policies.
security is a great concern.
security of patient's medical reports/prescription is prime
concern.
Mandatory access control(MAC) should be used to grant the access
to the resources.
in MAC, access rights are provided according to the level of
authority.for example a peon should not be allowed to access the
medical history/medical report of a patient.

Role base access control
(RBAC):
in role based access control, access rights are given according to
the role of employee.employee can access information which is
required to perform his/her job.employee can not access the
information which is not required to do his/her job.
RBAC makes employees more responsible because only employee who
wants information for his/her job can access the information, some
other employee who does not require information for his/her job
can not access this information.

the above security policies can be implemented with the help of IT
infrastructure and latest technologies.
a)encryption
b)Proxy server
the job of proxy server is to hide internal network from public
network(internet).
all the packets coming from outside world(internet) are first
received by the proxy server, now proxy server can forward this
packet to the internal host.hence making it almost impossible for
outsider to know the IP address of internal host.

c)Fire walls
every packet coming from outside world(internet) is
inspected/checked by fire wall against the rules defined by the
network admin.if incoming packet follows all the rules(if packet
is authorized)then fire wall allow this packet otherwise packet is
not allowed to enter.

Combination of proxy server and fire wall is used together.
d)Intrusion detection system:
ids is use to detect the unauthorized entry of an attacker in a
system
Advantages of IDS(intrusion detection system)
1) firewall can be configured to show the ports and ip addresses.
IDS can be configured to show the specific content with in a
packet.

2)an IDS is capable to analyze the types of security attacks.
it can also analyze the amount of security attack.

3)IDS maintains logs, these logs can help security manager to
design some new security policies.



Related Solutions

Purpose The purpose of this assignment is to give you an opportunity to demonstrate your ability...
Purpose The purpose of this assignment is to give you an opportunity to demonstrate your ability to identify emerging ethical issues in business, interpret the multitude of perspectives inherent in your case study, and model appropriate behaviour by recommending specific solutions. How to Proceed Select a case. It can be one of the textbook cases that we have not discussed during the course. It can also come from the outside world, perhaps a case you have been following in the...
"Gambling Greg" Assignment Outcomes: Demonstrate the ability to create and use structs Demonstrate the ability to...
"Gambling Greg" Assignment Outcomes: Demonstrate the ability to create and use structs Demonstrate the ability to create and use menus Demonstrate the ability to create and use an array of structs Demonstrate the ability to generate and use random numbers Program Specifications: Assume that gambling Greg often goes to the Dog Racing Track. Greg loves to bet on the puppies. In each race Greg will place a wager and pick a dog. The dog information will be stored in a...
Playing with strings Assignment Outcomes: Demonstrate the ability to create strings. Demonstrate the ability to manipulate...
Playing with strings Assignment Outcomes: Demonstrate the ability to create strings. Demonstrate the ability to manipulate strings. Demonstrate the ability to write well written code. Program Specifications: DESIGN and IMPLEMENT a short program that will: Allow the user to enter a string with up to 100 letters. Display the user-entered string: Forward Backward Vertical As a triangle made from the letters of the string Display the number of letters in the string. Once everything above is displayed, the program will...
The purpose of this assignment is to calculate and interpret an ANOVA table. For this assignment,...
The purpose of this assignment is to calculate and interpret an ANOVA table. For this assignment, use IBM SPSS Statistics. Part 1: Using the "Example Dataset," assess this statement using ANOVA: "People with different levels of education exercise for different amounts of time during the week." Select and conduct the appropriate ANOVA test to assess the statement. Export the ANOVA table to a Word document. Part 2: In 250-500 words, discuss the following regarding the use of ANOVA. Describe when...
Struct PERSON Assignment Outcomes: Demonstrate the ability to create structs using typedef Demonstrate the ability to...
Struct PERSON Assignment Outcomes: Demonstrate the ability to create structs using typedef Demonstrate the ability to create an array of structs Program Specifications: DESIGN and IMPLEMENT a program that will CREATE and use three different variables of type PERSON. Create a struct using the typedef command for a DATE. Create a struct for a PERSON with the following fields. name [this will be a string] birthdate [this will be a DATE] gender [this will be a char] annualIncome [this will...
Struct PERSON Assignment Outcomes: Demonstrate the ability to create structs using typedef Demonstrate the ability to...
Struct PERSON Assignment Outcomes: Demonstrate the ability to create structs using typedef Demonstrate the ability to create an array of structs Program Specifications: DESIGN and IMPLEMENT a program that will CREATE and use three different variables of type PERSON. Create a struct using the typedef command for a DATE. Create a struct for a PERSON with the following fields. name [this will be a string] birthdate [this will be a DATE] gender [this will be a char] annualIncome [this will...
Struct PERSON Assignment Outcomes: Demonstrate the ability to create structs using typedef Demonstrate the ability to...
Struct PERSON Assignment Outcomes: Demonstrate the ability to create structs using typedef Demonstrate the ability to create an array of structs Program Specifications: DESIGN and IMPLEMENT a program that will CREATE and use three different variables of type PERSON. Create a struct using the typedef command for a DATE. Create a struct for a PERSON with the following fields. name [this will be a string] birthdate [this will be a DATE] gender [this will be a char] annualIncome [this will...
Its purpose is to provide you an opportunity to demonstrate your ability to think like an...
Its purpose is to provide you an opportunity to demonstrate your ability to think like an economist by applying economic principles to interpret the logic of a real-world phenomenon. Please identify any ONE of the monetary policies during COVID 19 in the world, use macroeconomic theories to demonstrate the economic logic behind this monetary policy. Also, please discuss how different schools of economics think of this monetary policy. Do you agree or disagree with this monetary policy? Please use the...
Its purpose is to provide you an opportunity to demonstrate your ability to think like an...
Its purpose is to provide you an opportunity to demonstrate your ability to think like an economist by applying economic principles to interpret the logic of a real-world phenomenon. Please identify any ONE of the monetary policies during COVID 19 in the world, use macroeconomic theories to demonstrate the economic logic behind this monetary policy. Also, please discuss how different schools of economics think of this monetary policy. Do you agree or disagree with this monetary policy? Please use the...
The purpose of the self-assessment paper is to demonstrate your ability to apply psychological concepts and...
The purpose of the self-assessment paper is to demonstrate your ability to apply psychological concepts and theory to your own life. It is not a research paper. The paper must be at least four (4), but no more than five (5) pages in length and address one of the following topics: How I Can Apply Psychology to My Future Life- How can the information you have learned in this class play a role in your future life. Describe how this...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT