11 Mar Security Assessment Report for Fielder Medical Center
Scenario
Fielder Medical Center (FMC) is a federally funded healthcare facility that seeks to expand its business into the local sale of medical equipment. As FMC sought to improve its data management in alignment with digitization goals, it implemented a system to manage the licensing, certificates, and relevant professional documents for the doctors working at FMC. Doctors are required to log in and upload sensitive artifacts that prove they are current in their licensing to practice. These artifacts may contain personally identifiable information about the doctor, including real name, home address, social security number, and other sensitive data.
Aside from the digitization of data for convenient management within FMC, the main purpose of this system is to allow access by the government for the purpose of validating information and securing federal funds on a recurring annual basis.
Concerns about security were discussed at a recent board meeting, and an external security consulting firm was hired to conduct a security assessment of FMC’s systems. This report identifies several potential compliance issues that would require the system security plan (SSP) to be updated, including security controls that are in place or planned for meeting system requirements.
As FMC’s CISO (Chief Information Security Officer), you are responsible for identifying and developing a cyber strategy to address the risks identified in the attached “Security Assessment Report for Fielder Medical Center” to ensure that FMC’s security posture is brought into alignment with the Federal Information Security Management Act (FISMA) requirements. As the new FMC system includes only doctor information and does not include patient information, compliance focuses on FISMA requirements instead of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule requirements.
A. Summarize the gaps that currently exist in the company’s security framework as described in the attached “Security Assessment Report for Fielder Medical Center” (SAR).
B. For each of the five identified controls in Section 3.3 of the SAR, do the following:
1. Identify the associated risk rating as low, moderate, or high and explain the risk.
2. Justify FMC’s decision to remediate the risk associated with the identified control instead of accepting the risk based on compliance and industry guidelines and support the justification with industry-respected sources.
Note: Be sure to include all five controls in part B1, and all five controls in part B2. Your submission will be returned if one or more controls are missing from part B1 or part B2.
C. Discuss how FMC should remediate the risks with each of the five controls identified in Section 3.3 of the SAR. For each risk, include any assets, actions, or changes that will be needed for remediation.
Note: Be sure to include all five controls from part B. Your submission will be returned if one or more controls are missing from part C.
D. Develop a PCI DSS (Payment Card Industry Data Security Standard) –compliant policy to address the three concerns identified in Section 3.2.4 of the SAR, including the roles and responsibilities associated for each requirement identified within the SAR to meet PCI DSS compliance.
Our website has a team of professional writers who can help you write any of your homework. They will write your papers from scratch. We also have a team of editors just to make sure all papers are of HIGH QUALITY & PLAGIARISM FREE. To make an Order you only need to click Ask A Question and we will direct you to our Order Page at WriteDemy. Then fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.
Fill in all the assignment paper details that are required in the order form with the standard information being the page count, deadline, academic level and type of paper. It is advisable to have this information at hand so that you can quickly fill in the necessary information needed in the form for the essay writer to be immediately assigned to your writing project. Make payment for the custom essay order to enable us to assign a suitable writer to your order. Payments are made through Paypal on a secured billing page. Finally, sit back and relax.