NWSD Risk Analysis & Mitigation Plan -- 2
Budget: $250 – $750 AUD
You are a team of consultants hired by the National Work Safety Department (NWSD) to perform risk analysis and prepare a project plan for mitigating identified risks. The purpose of this assignment is to demonstrate your findings to the board of directors at the National Work Safety Department (NWSD) and convince them to hire your team for the implementation of this project too.
An important part of this project involves analysis and justification of how you discovered their information assets, the value of those assets, threats and vulnerabilities for those assets, and finally their corresponding mitigation strategies. Your “fact-finding” begins with no prior knowledge of the business. You begin this task with the information provided below as part of your discovery and continue with further investigation. You may use the threats and vulnerabilities that are consistent with the given scenario (shown below), but your “analysis” must not stop there. You are expected tocontinue with your “discovery” to find additional threats by making reasonable assumptions about the business.
As part of your narrative of the report and presentation, you should describe the techniques you used to discover information assets, threats, and vulnerabilities. In the case of some unusual threats, such as any threat associated with critical infrastructure, you should provide more details of your discovery.
After the fact-finding, you will produce a quantitative risk analysis of the form discussed in lectures and tutorials. You will then produce a qualitative analysis derived rigorously from the quantitative analysis. You need to specify the process you followed to move from the quantitative to the qualitative analysis.
An important part of this project involves analysis and justification of how you discovered their information assets, the value of those assets, threats and vulnerabilities for those assets, and finally their corresponding mitigation strategies. Your “fact-finding” begins with no prior knowledge of the business. You begin this task with the information provided below as part of your discovery and continue with further investigation. You may use the threats and vulnerabilities that are consistent with the given scenario (shown below), but your “analysis” must not stop there. You are expected tocontinue with your “discovery” to find additional threats by making reasonable assumptions about the business.
As part of your narrative of the report and presentation, you should describe the techniques you used to discover information assets, threats, and vulnerabilities. In the case of some unusual threats, such as any threat associated with critical infrastructure, you should provide more details of your discovery.
After the fact-finding, you will produce a quantitative risk analysis of the form discussed in lectures and tutorials. You will then produce a qualitative analysis derived rigorously from the quantitative analysis. You need to specify the process you followed to move from the quantitative to the qualitative analysis.
Related categories:
Data Processing
Research Writing
Risk Management
Data Analysis
IT strategy
Consulting
Project Planning