Week 2 Lab Essay

------------------------------------------------- Week 2 Laboratory: Part 1 Part 1: Define an Information Systems Security Policy Framework for an IT Infrastructure Learning Objectives and Outcomes Upon completing this lab, students will be able to complete the following tasks: * Identify risks and threats commonly found within the 7domains of a typical IT infrastructure * Define security policies to address each identified risk and threat as they are organized within the 7domians of a typical IT infrastructure * Align security policies to mitigate risks from threats and vulnerabilities found within the 7 domains of a typical IT infrastructure * Organize the security policies within an overall framework as part of an overall layered security strategy for the 7 domains of a typical IT infrastructure * Select the appropriate policy definitions needed throughout the 7domains of a typical IT infrastructure to mitigate the identified risks, threats, and vulnerabilities Week 2 Lab Part 1: Assessment Worksheet (PART A) List of Risks, Threats, and Vulnerabilities Commonly Found in an IT Infrastructure Overview The following risks, threats, and vulnerabilities were found in a healthcare IT infrastructure serving patients with life-threatening situations. Given the following list, select where the risk, threat, or vulnerability resides in the seven domains of a typical IT infrastructure. Place your answers under the “Primary Domain Impacted” column. Risk – Threat – Vulnerability | Primary Domain Impacted | Unauthorized access from public Internet | LAN TO WAN | User destroys data in application and deletes all files | SYSTEM / APPLIACATION | Hacker penetrates your IT infrastructure and gains access to your internal network | LAN TO WAN | Intra-office employee romance “gone bad” | USER | Fire destroys the

