430 W7 Benchmark – Developing Contingency Strategies for Information System UG
Review Details
Take a moment to review the details of this assignment below and gather any necessary files. Once you’re ready to submit your assignment, move on to Step 2.
Assessment Traits
Benchmark
Requires Lopeswrite
Assessment Description
24/7 monitoring of all network activity is an invaluable tool for enhancing your security posture. An effective Incident Response Plan (IRP) is essential to mitigation of attacks, while a Disaster Recovery Plan (DRP) provides support for unexpected environmental obstacles to information systems. For both IRP and DRP, a company must develop strategies to recover from unexpected interruptions, and exercise these plans to ensure all applicable personnel are prepped and aware of their roles. In Topic 5, a minor Business Impact Analysis (BIA) was conducted, which identified the critical assets to the company. These assets will be used to aid in the development of a contingency plan to ensure business continuity in the presence of an event.
This assignment exercises the analysis and development of a Lite Contingency Plan (BIA, IRP, DRP, and Business Continuity Plan: BCP). The development of a workflow diagram is essential in displaying the relationship between the four components. This is critical for the IRP and DRP, as an IRP can launch a DRP when a threat disrupts a system through ransomware, DDoS, or other malicious attacks against a system.
Use the following guidelines to create an 8- to 12-page report using the same corporate profile selected earlier.
Business Impact Analysis
1. In one to two paragraphs, summarize the objective of conducting a BIA for your selected company. Describe the benefits, potential outcomes, and company enhancements.
2. Obtain the list of threats against the assets identified in your Topic 5 assignment, “Risk Management Assessment and Control,” and place them in a table.
3. Prioritize this list from highest impact to lowest impact to the company.
4. Add a column and describe how loss of the process, system, data, etc., will impact the company.
5. Assuming worst-case scenario, add a column and describe the appropriate measures to recover from the threat.
Incident Response Plan (IRP)
In three to four pages, detail an IRP to include:
1. Brief overview
2. Roles and responsibilities (from Users to CISO)
3. Reporting guidelines
4. Example workflows diagram – Event to resolution
5. Explain the six stages of incident handling as it relates to the company
6. Escalation procedures with an associated chart
Disaster Recovery Plan (DRP)
Establish a DRP Policy in one to two pages that contains the following in alignment with the company:
1. Purpose
2. Scope
3. Roles and responsibilities
4. Resource requirements
5. Training requirements
6. Exercise and testing schedules (include IRP exercise and schedules)
7. Plan maintenance schedules
Business Continuity Plan (BRP)
In three to four pages, close out the assignment with a complete BC Plan that includes the following:
1. Describe which usage strategy (Hot site, Warm site, or Cold site) the company will use and why (explain the benefit to the company).
2. Explain how the company will use and sustain the usage strategy.
3. Detail the critical systems/assets recovery procedures.
4. Provide processes to reestablish business operations and security operations. Include disaster to alternate site and restoration back to original state.
5. Provide and describe a worst-case scenario timeline (disaster to recovery).
6. Describe readiness, training, exercises, and BC process reviews/updates.
Include diagrams, tables, and charts as directed by the instructor.
APA style is not required, but solid academic writing is expected.
This assignment uses a rubric. Review the rubric prior to beginning the assignment to become familiar with the expectations for successful completion.
You are required to submit this assignment to LopesWrite. Refer to the LopesWrite Technical Support articles for assistance.
Benchmark Information
This benchmark assignment assesses the following programmatic competencies:
B.S. Cyber Security
6.2 Conduct an exercise to test the disaster recovery plan in a predetermined scenario.
7.2 Perform activities to mitigate possible or real-time threats (e.g., system monitoring and incidence response).