Such frameworks usually combine security and risk management functions into a tri-tiered risk management approach assessing the organization, business processes, and the environment of operation (NIST, 2018).
Such frameworks usually combine security and risk management functions into a tri-tiered risk management approach assessing the organization, business processes, and the environment of operation (NIST, 2018).
September 4, 2020 Comments Off on Such frameworks usually combine security and risk management functions into a tri-tiered risk management approach assessing the organization, business processes, and the environment of operation (NIST, 2018). Uncategorized Assignment-helpBetween July 2018 and July 2019, the healthcare industry experienced over a 29% increase of security breaches than that of the previous year as hackers determined to obtain sensitive patient information have gained momentum exploiting various healthcare-related vulnerabilities (HHS, 2019).Data breaches, malicious activities resulting in a multibillion-dollar range of annual losses, involve incidents that derive from unauthorized access and subsequent compromise to the confidentiality, availability, and integrity of sensitive data. Contributing to the compounded risks which developed from enhanced threats and expanding threat exposure, the rapid growth of cybersecurity incidents and data security breaches affecting the healthcare industry have become an increasing concern for information security professionals worldwide. Although the healthcare sector is vulnerable to cyber-attacks targeted at infrastructure, services, and interconnected devices, the impact of healthcare data breaches may be more profound than threat vectors experienced with other prominent industries when accounting for risks to patient safety and wellbeing (Ahmed, Naqvi, & Josephs, 2019).Researchers founded risk-based models such as the Risk Management Framework (RMF) on the premise of mitigating risks inherent within the information technology (IT) enterprise architecture and system development lifecycle (SDLC) and reducing security breaches. Such frameworks usually combine security and risk management functions into a tri-tiered risk management approach assessing the organization, business processes, and the environment of operation (NIST, 2018). Adopting risk-based models such as the RMF model within the organization provides information security managers in the healthcare sector the capability to integrate enterprise-level cybersecurity and enhance the risk management experience through defined roles and responsibilities.As we discuss contingency planning, risk assessment, and risk control this week, let’s reflect on the similarities and differences of other risk-based models like the RMF.What are some other risk-based models and how can they be implemented in the organization you chose?-IanReferences:Ahmed, Y., Nadqvi, S., & Joephs, M. (2019, May). Cybersecurity metrics for enhanced protection of healthcare IT systems. International Symposium on Medical Information and Communication Technology (ISMICT) (pp. 1-9). Birmingham City: IEEE. doi:10.1109/ISMICT.2019.8744003NIST. (2018). Risk Management Framework for information systems and organizations (2 ed.). Gaithersburg, Maryland, USA: National Institute of Standards and Technology. doi:10.6028U.S. Department of Health and Human Services. (2019). DOI secuity assessment & authorization. Retrieved December 2019, from U.S. Department of the Interior – Office of Chief Information Officer: https://www.doi.gov/ocio/customers/assessmentThe company I chose is CEMEX.https://www.cemex.com/about-us/company-profile


