Question

In: Computer Science

You are a cybersecurity consultant and just met with the CISO’s team. During this meeting on...

You are a cybersecurity consultant and just met with the CISO’s team. During this meeting on the cybersecurity readiness of the company, CISO showed you risk matrices that have more colors than the rainbow. Later, during your interviews, you found out that most of the cybersecurity staff is pretty grim and thinks that a breach will lead to a very big loss and bankrupt the company.

Now it is your time to gather your thoughts to write a report for the CEO. You get your Summer Berry Panna Cotta Frappuccino from Starbucks and start formulating some of the key points you’d like to raise. These include: Reason to move away from risk matrices, alternative methods to assess risk, a plan to deal with resistance to using quantitative risk assessment while explaining why there is such a resistance, and activities of a risk management workshop where you get the cybersecurity staff ready for quantitative analysis.

This question covers almost everything the books discusses. Take your time and discuss in depth.

Solutions

Expert Solution

Reasons to move away from risk matrices:

The risk matrix is used to categorize the risks and show their impact on the system. Each risk is given a score and they are ranked as per the score. The matrices are used to show the potential risks of the system. However, the problem is that some of those risks might never occur in the system. This is because it is hard to find out the exact value for non-linear type of risks. In those cases, one has to use their instincts and experiences.

These matrices also have low resolution and hence they look almost alike. If they give equal weight to impact and probability of an incident in common situations, it can create problems regarding how to choose the right approach.

Alternative methods to assess risk:

1. What-if approach can be used to recognize the potential threats in the system. These types of questions help in understanding what can actually go wrong and when. It is similar to brainstorming tasks and requires knowledge of the subject.

2. A checklist of threats can be used to identify them in the current system. This type of work also depends on the checklist's quality and user's experience.

3. Hazard operability study is also useful to know about the potential threats. It also requires leadership and is time consuming as well. This is because it requires in depth knowledge of operations, work areas, and processes.

Plan to deal with resistance to quantitative risk assessment:

To deal with such resistance, the overall activity of quantitative assessment can be divided into three parts such as assessment, management, and communication. The plan also includes identification, prioritization, and categorization of software and hardware. This can help in achieving key objectives of reliability business concepts.

It is also required to assess the key controls related to security in different applications. It helps in preventing the defects and other weaknesses.

Activities of a risk management workshop:

In the beginning the objectives are defined and activities in this stage are:

  • Risk prioritization
  • Action plan assignment for different risks
  • Communication with stakeholders
  • Working with varying viewpoints
  • Understanding control activities

In the next stage, following activities are performed:

  • Risk mapping onto heatmaps
  • Creation of risk registers
  • Finding errors in manual reports
  • Communicating the findings

Related Solutions

Recently met with your clients, Mr. and Mrs. Smith. During that meeting they gave you a...
Recently met with your clients, Mr. and Mrs. Smith. During that meeting they gave you a lot of information about themselves and their family. They would like your help with financial planning, although they don't really know what specifically they need help with or how you can help them. You are now preparing for another meeting with them. Explain EACH of these topics in enough detail for them to get an overview and an understanding of some of the key...
You are meeting with your healthcare team to round in the ICU and the discussion is...
You are meeting with your healthcare team to round in the ICU and the discussion is started regarding utilization of medications to treat COVID-19 patients. The attending physician asks if you could review the literature regarding azithromycin and chloroquine/hydroxychloroquine as these have been studied in the literature. Please provide a review regarding the safety and efficacy of these agents in the treatment of COVID-19.
As a Health Care IT consultant, you will work with various team members at the corporate...
As a Health Care IT consultant, you will work with various team members at the corporate level to gather information and analyze which of the following? (Select all that apply)    The efficacy of each electronic health records system     The possibility of getting a kick-back for recommending a particular electronic health records system     The cost-benefit factors of each electronic health records system     The cost effectiveness of each electronic health records system     The personal relationships corporate team...
It is December 10th and you just met with your financial advisor, who suggested that you...
It is December 10th and you just met with your financial advisor, who suggested that you begin putting $5,000 into a Roth RIA at the beginning of each year, starting next month. Your advisor says that, although there is no guarantee, you could average an annual return of 8% over the next twenty (20) years with the right mix of investments. You want to know just how big of a "nest egg" you can create if you take her advide...
– Malware – Your cybersecurity team is finally getting a break after dealing with an outbreak...
– Malware – Your cybersecurity team is finally getting a break after dealing with an outbreak of the new malware W32/CoinMiner hit the corporate network, impacting productivity over the holiday weekend. It was determined this was caused by one of the sales folks who clicked on a “get rich quick” link. The attackers were able to use your company’s computing resources to generate a cryptocurrency mining pool, negatively impacting server performance. As your team is headed home for some much...
2. You are an executive for a manufacturing company. You have just attended a meeting in...
2. You are an executive for a manufacturing company. You have just attended a meeting in which the CEO has approved a new production method that may leak poison into a river and endanger the salmon spawn. You have always been concerned about the environment and you are very much against endangering the salmon spawn. You have to decide whether you are going to oppose this decision or remain silent. List the three most important considerations that are affecting your...
You are a member of a consultant team providing services to Dinosaur, LLC. Dinosaur is considering...
You are a member of a consultant team providing services to Dinosaur, LLC. Dinosaur is considering using benchmarking as it is interested in cost reduction. Your supervisor assigns you to prepare a brief memo explaining benchmarking to Dinosaur's management.
You are a meeting planner who was just contacted by an out of town client to...
You are a meeting planner who was just contacted by an out of town client to produce and “Indy 500” high roller party for 500 VIPs at the Sheraton Desert Inn. You are purchasing a band for $3,000. You are estimating your racing flag centerpiece cost (material and labor) to be $20 per table (50 tables). You are renting black and white checked scupltchair covers ($4.95) from a local linen company that will install the covers. You are estimating your...
You have been asked, as a digital health professional, to attend a team meeting at your...
You have been asked, as a digital health professional, to attend a team meeting at your hospital to discuss discharge plans for Mildred Mason. She is a 68 year old widow, hospitalized for a fractured wrist and ankle and a head injury resulting from a fall at home.   She is almost ready for discharge from acute care, but the team is concerned that she will need care in the short term. Because of some problems that may have led to...
You are part of a consultant team hired to improve the VVCS Company’s organizational structure which...
You are part of a consultant team hired to improve the VVCS Company’s organizational structure which has communication and coordination lapses. This company actual organizational design is of a more mechanistic nature and is characterized by: - a very high level of official rules, regulations, and procedures; - almost all decisions are made at the top levels of the organization; - there is a high homogeneous basis of departmentalization; - there is a very clearly defined chain of command; -...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT