Is411 Assignment 4

626 Words3 Pages
Risk Management in a Business Model Rabecca Summerlin IS411: Security Policies and Implementation Issues Sandro Tuccinardi 5/25/2014 Introducing the Who?, What?, When?, Why? of Risk Management in the health care organization. The ‘who’ refers to who will be at risk ‘the patient’ or who may cause the risk such as a ‘hacker’ or who will handle the risk such as the ‘IT personnel’. The ‘what’ is the risk and how you can mitigate the risk by implementing the information security systems policies. The ‘when’ is when will these risks harm this organization and ‘when’ will the countermeasures be applied to avoid these risks. The ‘why’ is the reason why these risks should be mitigated. There are many risks that are associated with any healthcare organization that can be prevented by implementing Information Security Strategies and critical IT components. One risk is the identity theft of the patient’s personal information such as social security numbers, credit card information, personal address, phone numbers, and insurance account information. Another risk could be a possible internal breach of security vulnerabilities such as cross-site scripting and SQL injections that could be exploited by either an unauthorized user or an employee via the internet or the intranet that could compromise the confidentiality of sensitive information. Two more probable risks would be not having a proper disaster recovery policy in place and the data not being correctly backup and the use of a single-on to every computer which could lead to unauthorized access. My current healthcare organization can mitigate the risks by implementing the proper information systems policies that to protect the organization from any unauthorized user. These policies should include how to protect and how to use the IT technology such as making sure you log off when you leave your computer unintended
Open Document