Security Management & Compliance

Part 1:
Governance (20%)
Design a tailored IT Governance system using COBIT 2019 Design Factors for the business you work for or for a selected organisation e.g. the HSE. (You do not have to implement a full Governance system, but you should have a list of priorities for your selected organisation to focus on)

Figure 1: Governance System Design Workflow
Include;
• A description of the organisation you are tailoring the governance system for. The enterprise strategy/goals are set out here. Discuss what sort of role does I&T play in the organisation? Has the enterprise suffered from any IT problems or had any Cybersecurity incidents in the past? Have similar organisations suffered breaches? This description will then be used during the Design Factors stage.
• Apply the COBIT Design Toolkit and determine what are the recommended focus points for the organisation.

Reflect on the information received in 1500 words.
• Discuss the feedback the Design Toolkit gave you. What Governance and Management Objectives and Activities should your business be focusing on? If the documentation for that Objective is not on Blackboard then please request this from your Lecturer.
• Was this Design Factor process useful? How can this benefit your organisation or HSE?
• What aspects were not helpful, how would you critique the Design Factor toolkit and the feedback the tool gave you?
• Are there other Governance frameworks that would be more beneficial to use and what type of insights would using those frameworks give compared to COBIT 2019 e.g. does NIST/ISO prescribe a better way to construct an IT Governance system for our organisation?
• Link your reflection to any research/best practices in this area.

Part 2:
Risk Management (30%)
Conduct a risk assessment for specific areas of concern for the business you work for or for a selected organisation e.g. the HSE.
Scenario: The Senior Management Team (SMT) is accustomed to receiving risk assessments using qualitative risk assessment charts/heat maps. The CEO of the organisation was in discussion with a CEO from another organisation who recommended to him the use of Factor Analysis of Information Risk (FAIR). The CEO wonders if FAIR will give better insights into the risks the business is facing from threat actors in the Cybersecurity sphere. The CEO wants you to investigate how FAIR could be useful both internally and externally. You must;
• Identify 2 high priority risk areas that need to be addressed for your selected organisation.
• Prepare a document that will be presented to the SMT. Explain the current risk position of the organisation and how you intend to mitigate those risks for the organisation.

You should display both a quantitative and qualitative risk analysis to SMT.

Reflect on the work that you have done above in 1500 words.

• Make a recommendation to the CEO on if you feel the quantitative FAIR can provide value to the company going forward or if the traditional approached of qualitative heat maps is sufficient for monitoring Cybersecurity risk going forward. Link your comments to any research in this area. Come to a conclusion on where and when it is appropriate to use each approach going forward.
• You may choose to use Frameworks and Tools from NIST/ISO/CIS/FAIR to assist you in your risk analysis.

Last Completed Projects

topic title academic level Writer delivered