This document outlines tasks for developing a risk management plan for Health Network Inc., a healthcare services organization. It provides background on the company and its IT infrastructure. The tasks include creating a risk management plan, risk assessment plan, and risk mitigation plan. It also includes tasks for developing a business impact analysis plan, business continuity plan, and disaster recovery plan to address risks identified. The document provides evaluation criteria for each deliverable.
Assignment 1 Human Resource Management Overview Due Week 4 an.docx
1. Assignment 1: Human Resource Management Overview
Due Week 4 and worth 200 points
Using the course readings, articles, and your personal
experiences, address the role of human resource management.
Write a six to eight (6-8) page paper in which you:
1.Determine key roles that human resource management plays in
the health care field..
2.Evaluate three to five (3-5) functions of human resource
management in terms of their level of support to the health care
field, and then select which one you believe is the primary
function in furthering the health care field..
3.Analyze the role of human resource management in an
organization’s strategic plan..
4.Use at least three (3) quality academic resources in this
assignment. Note: Wikipedia and other Websites do not qualify
as academic resources..
Your assignment must follow these formatting requirements:
•Be typed, double spaced, using Times New Roman font (size
12), with one-inch margins on all sides; citations and references
must follow APA or school-specific format. Check with your
professor for any additional instructions..
•Include a cover page containing the title of the assignment, the
student’s name, the professor’s name, the course title, and the
date. The cover page and the reference page are not included in
2. the required assignment page length..
The specific course learning outcomes associated with this
assignment are:
•Appraise the aspects of managing human resources (HR) in
health care organizations. .
•Use technology and information resources to research issues in
health care human resources management..
•Write clearly and concisely about health care human resources
management using proper writing mechanics..
RegisterRisk Register#RiskImpact on ProjectCost
$LikelihoodImpact Mitigating ActionsContingencyRisk
OwnerDeadline101<Identify the risk>Brief description of risk
and impact on costs, schedule etc$Very
UnlikelyNegligible<Describe what is currently done on the
project to reduce the impact of the risk.><Describe the course
of action if the risk does materialize: alternate solution,
reduction in functionality etc.>Person
responsibleMM/DD/YY102<Identify the risk>Brief description
of risk and impact on costs, schedule
etc$UnlikelyMarginal<Describe what is currently done on the
project to reduce the impact of the risk.><Describe the course
of action if the risk does materialize: alternate solution,
reduction in functionality etc.>Person
responsibleMM/DD/YY103<Identify the risk>Brief description
of risk and impact on costs, schedule etc$Moderately
LikelySignificant<Describe what is currently done on the
project to reduce the impact of the risk.><Describe the course
of action if the risk does materialize: alternate solution,
reduction in functionality etc.>Person
responsibleMM/DD/YY104<Identify the risk>Brief description
of risk and impact on costs, schedule
3. etc$LikelyCritical<Describe what is currently done on the
project to reduce the impact of the risk.><Describe the course
of action if the risk does materialize: alternate solution,
reduction in functionality etc.>Person
responsibleMM/DD/YY105<Identify the risk>Brief description
of risk and impact on costs, schedule etc$Very
LikelyCrisis<Describe what is currently done on the project to
reduce the impact of the risk.><Describe the course of action if
the risk does materialize: alternate solution, reduction in
functionality etc.>Person responsibleMM/DD/YY106<Identify
the risk>Brief description of risk and impact on costs, schedule
etc$Very UnlikelyNegligible<Describe what is currently done
on the project to reduce the impact of the risk.><Describe the
course of action if the risk does materialize: alternate solution,
reduction in functionality etc.>Person
responsibleMM/DD/YY107<Identify the risk>Brief description
of risk and impact on costs, schedule
etc$UnlikelyMarginal<Describe what is currently done on the
project to reduce the impact of the risk.><Describe the course
of action if the risk does materialize: alternate solution,
reduction in functionality etc.>Person
responsibleMM/DD/YY108<Identify the risk>Brief description
of risk and impact on costs, schedule etc$Moderately
LikelySignificant<Describe what is currently done on the
project to reduce the impact of the risk.><Describe the course
of action if the risk does materialize: alternate solution,
reduction in functionality etc.>Person
responsibleMM/DD/YYBRisk Identifier—a descriptive name or
number. Use this for tracking across project
documentsCIdentify the risk and relevant triggers that may
cause the risk to be realizedDDiscuss the potential impact this
risk may have on costs and/or scheduleEIdentify the cost
associated with this riskFLikelihood is a measure of the
probability of the event occurring: Very Unlikely, Unlikely,
Moderately Likely, Likely, Very LikelyGImpact measures the
effect on scope, cost, and/or schedule -- Negligible, Marginal,
4. Significant, Critical, or Crisis.HRisk Level is the resultant of
Likelihood and Impact Low, Moderate, or High.ISpecify
planned mitigation strategies: Preventative (implement
immediately) OR Contingency (implement if/when risk
occurs)JIdentify who is responsible for undertaking each
mitigation action(s)KIdentify the status of the risk: Open,
Closed, New etc
1
2
3
4
5
6
A
B
C
D
#
Risk
Impact on Project
101
<Identify the risk>
Brief description of risk and impact on costs, schedule etc
102
<Identify the risk>
Brief description of risk and impact on costs, schedule etc
103
<Identify the risk>
Brief description of risk and impact on costs, schedule etc
Risk Register
Your Organization
5. .
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
Enter details about the organization and it IT Infrastructure.
•
•
•
organization
division
organization's
organizational
ISOL 533 - InfoSecurity & Risk
6. Management University of the Cumberlands
organization .
organization
organization d
organization'
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
organization changes to the
systems, applications and organizational data can undermine the
organization's
violations of federal or state mandates and laws can
lead to major . potential to impact the
organization
organization
7. ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
organization
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
central respoitory accessible via the
orporate
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
8. ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
organization
organization
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
ISOL 533 - InfoSecurity & Risk
Management University of the Cumberlands
ISOL 533 - Information Security and Risk Management
Risk Management Plan
University of the Cumberlands
Executive Summary
<Review the Scenario on Page #2 of the publisher’s Project:
Risk Management Plan. Summarize the information about the
company provided in the scenario and place it into this section
of the report. Remove these instructions and all other
instructions below before submitting the document for
grading.>
This Risk Management Plan covers the Risks, Threats and
Weaknesses of the Health Network, Inc. (Health Network).Risks
- Threats – Weaknesses within each domain
<Using the Threats listed on Page #3 of the publisher’s Project:
Risk Management Plan and the 7 Domains diagram on Page #3
10. Deliverables
As discussed in this course, risk management is an important
process for all organizations. This is particularly true in
information systems, which provides critical support for
organizational missions. The heart of risk management is a
formal
risk management plan. The project activities described in this
document allow you to fulfill the role of an employee
participating in the risk management process in a specific
business situation.
The project is structured as follows:
Project Part Deliverable
Project Part 1 Task 1: Risk Management Plan
Task 2: Risk Assessment Plan
Task 3: Risk Mitigation Plan
Project Part 2 Task 1: Business Impact Analysis (BIA) Plan
Task 2: Business Continuity Plan (BCP)
Task 3: Disaster Recovery Plan (DRP)
Task 4: Computer Incident Response Team (CIRT) Plan
Submission Requirements
All project submissions should follow this format:
11. tible
-point, double-space
Scenario
You are an information technology (IT) intern working for
Health Network, Inc. (Health Network), a fictitious health
services organization headquartered in Minneapolis, Minnesota.
Health Network has over 600 employees throughout the
organization and generates $500 million USD in annual
revenue. The company has two additional locations in Portland,
Oregon and Arlington, Virginia, which support a mix of
corporate operations. Each corporate facility is located near a
co-
location data center, where production systems are located and
managed by third-party data center hosting vendors.
Company Products
Health Network has three main products: HNetExchange,
HNetPay, and HNetConnect.
HNetExchange is the primary source of revenue for the
company. The service handles secure electronic medical
messages that originate from its customers, such as large
hospitals, which are then routed to receiving customers such as
13. and update their profiles using Internet-accessible HTTPS Web
sites.
Information Technology Infrastructure Overview
Health Network operates in three production data centers that
provide high availability across the company’s products.
The data centers host about 1,000 production servers, and
Health Network maintains 650 corporate laptops and
company-issued mobile devices for its employees.
Threats Identified
Upon review of the current risk management plan, the following
threats were identified:
production systems
-
owned assets, such as mobile devices and laptops
various events, such as natural disasters, change
management, unstable software, and so on
the Internet
der threats
15. For the first part of the assigned project, you must create an
initial draft of the final risk management plan. To do so, use
the template provided in class:
Evaluation Criteria and Rubrics
competencies covered in the course thus far?
management plan in the outline?
asoning, and
decision-making skills in identifying key components
and compliance laws and regulations?
-developed draft
with proper grammar, spelling, and punctuation?
Project Part 1 Task 2: Risk Assessment Plan
After creating an initial draft of the risk management plan, the
second part of the assigned project requires you to create a
draft of the risk assessment (RA) plan. To do so, use the
template provided in class:
Evaluation Criteria and Rubrics
competencies covered in the course relating to risk
assessments?
17. have been assigned to develop this new plan using the
template provided in class.
Evaluation Criteria and Rubrics
-quality risk mitigation plan
based on material provided in the course?
parts of the project to build out a risk mitigation plan?
-developed draft
with proper grammar, spelling, and punctuation?
Project Part 2 Task 1: Business Impact Analysis (BIA) Plan
This part of the project is a continuation of Project Part 1 in
which you prepared an RA plan and a risk mitigation plan for
Health Network. Senior management at the company has
decided to allocate funds for a business impact analysis (BIA).
Because of the importance of risk management to the
organization, senior management is committed to and supportive
of
performing a BIA. You have been assigned to develop the BIA
plan.
Evaluation Criteria and Rubrics
19. plan. You have been assigned to develop this new plan.
Winter storms on the East Coast have affected the ability of
Health Network employees to reach the Arlington offices in a
safe and timely manner. However, no BCP plan currently exists
to address corporate operations. The Arlington office is
the primary location for business units, such as Finance, Legal,
and Customer Support. Some of the corporate systems,
such as the payroll and accounting applications, are located
only in the corporate offices. Each corporate location is able
to access the other two, and remote virtual private network
(VPN) exist between each Production data center and the
corporate locations.
The corporate systems are not currently being backed up and
should be addressed in the new plan. The BCP should also
include some details regarding how the BCP will be tested.
You may refer to the following additional resources to help you
and your team develop a BCP, and you may use a BCP
template if found during your research.
References:
22. Project Part 2 Task 4: Computer Incident Response Team
(CIRT) Plan
By now you should have developed an RA, a risk mitigation
plan, and a BIA, BCP, and DRP.
In this part of the project, you will create a CIRT plan for
Health Network. The company headquarters (HQ) handles all
incidents because the information security organization is
located in Minneapolis, so the plan will have its roots at HQ.
Make sure to incorporate your instructor’s feedback on earlier
submissions if applicable to the CIRT plan.
Evaluation Criteria and Rubrics
submissions?
al, well-developed report
with proper grammar, spelling, and punctuation?
Health Network, Inc.
23. HNetPay
Payment
Database
View Bill –
Make Secure
Payments
View Bill -
Make Secure
Payments
HNetConnect Directory
Database
Doctors
Update
Profile
Customers
Query
HNetExchange
Message Server
(Primary Revenue)
Hospitals
(Customer)
Send Secure
Messages
Clinics
(Customer)
Receive Secure
Messages
View Bill -
Make Secure
Payments
Credit Card Processing Organization
Update
Profile
View Bill -
Make Secure
Payments
24. Update
Profile
Corporate Offices
Minneapolis
Arlington
Portland
650 Laptops/Mobile Devices
Data Centers
*Minneapolis
*Arlington
*Portland
1000 Servers
Loss of company data due to hardware removed from production
systems
Loss of customers due to production outages
Internet threats due to accessibility via internet
Loss of company information due to lost/stolen laptops/mobile
devices
Insider threats
Change in regulatory landscape impacting operations
Internet
Web
Server
(HNetConnect)
Application
Server
(HNetPay)
Database