Write My Paper Button

WhatsApp Widget

Write My Paper Button

WhatsApp Widget

Project 1: Developing a Risk Management Plan Purpose This project establishes a foundation for managing cybersecurity risk at Sabine Coastal Health Network (SCHN).

Project 1: Developing a Risk Management Plan

 

Purpose

This project establishes a foundation for managing cybersecurity risk at Sabine Coastal Health Network (SCHN).

Use the separate SCHN scenario to determine the organization’s operating environment, major risk concerns, compliance responsibilities, and risk management needs. Your work should demonstrate that you understand how cybersecurity risk management supports organizational decision-making.

This project primarily supports the Prepare activities of the NIST Risk Management Framework.

 

Required Reading

Before completing Project 1, review all assigned Week 1 and Week 2 readings:

  • Chapter 1: Risk Management Fundamentals
  • Chapter 2: Managing Risk: Threats, Vulnerabilities, and Exploits
  • Chapter 3: Understanding and Maintaining Compliance
  • Chapter 4: Developing a Risk Management Plan
  • Chapter 7: Identifying Assets and Activities to Be Protected

You should also use the assigned NIST Risk Management Framework material as directed by your instructor.

The textbook and NIST RMF should serve as the primary sources for this project.

 

What to Focus On

As you review the readings and the SCHN scenario, consider:

  • What does risk mean in the context of SCHN?
  • What assets, operations, information, and services appear important to the organization?
  • What types of threats and vulnerabilities could affect SCHN?
  • What sources of risk involve technology, people, third parties, physical facilities, or environmental conditions?
  • What legal, regulatory, contractual, or industry requirements may affect SCHN?
  • What organizational, operational, financial, compliance, technological, and environmental conditions should influence SCHN’s risk management decisions?
  • Who should participate in risk management decisions?
  • How should risks be identified, evaluated, communicated, addressed, and reviewed?
  • What information will SCHN need as it moves into more detailed risk analysis in later projects?

Do not attempt to solve every cybersecurity problem described or implied by the scenario. Your goal is to establish a reasonable foundation and process for managing risk.

 

Assignment

Using the SCHN scenario, prepare a risk management plan addressing the following areas.

1. Organizational Context

Briefly explain SCHN’s purpose, operating environment, size, resources, and other organizational conditions that should influence its approach to cybersecurity risk.

Your discussion should reflect the organization described in the scenario, not a generic healthcare organization.

2. Purpose and Scope of the Risk Management Plan

Explain why SCHN needs a risk management plan and identify what the plan should cover.

Establish reasonable boundaries based on SCHN’s operations, facilities, technology environment, external dependencies, and available resources.

You are not expected to identify every system, employee, device, vendor, or facility individually.

3. Risk Environment

Identify several general sources of cybersecurity risk that SCHN should consider when developing its risk management process.

Consider different types of threats and vulnerabilities suggested by the scenario. Explain why these sources of risk matter to SCHN without conducting a detailed threat or vulnerability assessment.

4. Risk Management Approach

Describe the general process SCHN should use to identify, evaluate, respond to, communicate, and monitor cybersecurity risk.

Your approach should reflect the principles discussed in the assigned readings and should recognize that risk cannot normally be eliminated completely.

Your recommendations should also reflect SCHN’s available resources and the need to provide risk-based justification for significant cybersecurity expenditures.

The purpose of this section is to establish how risk will be managed, not to perform the complete risk assessment.

5. Roles and Responsibilities

Identify the organizational roles or groups that should participate in SCHN’s risk management process.

Explain their general responsibilities and why their involvement is important.

A detailed organizational chart or individual job descriptions are not required.

6. Compliance Considerations

Identify the major types of legal, regulatory, contractual, or industry requirements that may influence SCHN’s cybersecurity risk decisions.

Explain how these requirements should affect the risk management process.

A detailed compliance audit or legal analysis is not required.

7. Preliminary Assets and Activities

Identify broad categories of assets and business activities that appear important based on your review of the SCHN scenario.

This is a preliminary examination only. Do not create a complete asset inventory.

Your purpose is to recognize the general types of organizational resources and activities that will require more detailed examination in Project 2.

8. Management Summary

Conclude with a brief summary written for SCHN management.

Explain:

  • Why the proposed risk management approach is appropriate for SCHN
  • The most important risk management issues management should understand
  • What the organization should examine next

Write this section for a manager who may not have a technical cybersecurity background.

 

What This Project Should Not Include

Project 1 establishes the foundation for SCHN’s risk management process. It is not a complete cybersecurity risk assessment.

Do not include:

  • A detailed inventory of individual hardware, software, medical devices, employees, vendors, or data
  • A complete asset valuation or classification
  • A comprehensive threat or vulnerability assessment
  • Technical vulnerability testing or penetration-testing results
  • Calculated risk scores or detailed likelihood and impact calculations
  • A complete risk register
  • Detailed security-control evaluations
  • Specific cybersecurity products or technical configurations
  • A detailed cybersecurity budget
  • Specific recommendations for how SCHN should spend its cybersecurity funds
  • Cost-benefit calculations for individual controls
  • A complete incident response, disaster recovery, or business continuity plan
  • A business impact analysis
  • A full compliance audit or legal analysis
  • A detailed risk mitigation plan

You may mention assets, threats, vulnerabilities, compliance concerns, existing safeguards, financial constraints, and other conditions when they help explain SCHN’s risk environment. However, detailed analysis of these areas will occur in later projects.

Financial information provided in the scenario should help you understand SCHN’s organizational constraints and determine whether your proposed risk management approach is realistic. This project is not a budgeting exercise.

 

Use of the SCHN Scenario

The SCHN scenario is provided in a separate document. You are responsible for locating, interpreting, and evaluating the information needed for your analysis.

Do not simply restate or summarize the scenario.

Use scenario information to support your conclusions and recommendations.

When information is not provided, you may make a reasonable assumption when necessary. Clearly identify significant assumptions and explain why they are reasonable.

Do not add facts to the SCHN scenario simply because an AI system suggests them. Clearly distinguish between information provided in the scenario and assumptions made during your analysis.

 

AI Use and Professional Judgment

You are required to use an approved generative AI tool as a junior analyst during this project.

AI may assist you in:

  • Examining the scenario from different perspectives
  • Developing questions
  • Organizing ideas
  • Testing assumptions
  • Reviewing your reasoning
  • Identifying weaknesses or missing considerations
  • Improving communication

AI should support your analysis, but you remain responsible for the final decisions and recommendations.

When using AI:

  • Do not assume an AI response is correct.
  • Compare important AI-generated claims with the SCHN scenario, assigned readings, NIST guidance, or other appropriate sources.
  • Watch for information that AI may have assumed or invented about SCHN.
  • Determine what information you will accept, modify, investigate further, or reject.
  • Be prepared to explain and defend the decisions included in your final project.

The assigned ISC2 and SANS articles demonstrate why human judgment, validation, and accountability remain important even as AI use increases in cybersecurity.

 

AI Prompt and Evaluation Log (Turn in separately)

Submit the required AI Prompt and Evaluation Log as an appendix.

Your log must include at least three meaningful AI interactions and use the required fields:

  • Purpose
  • Complete Prompt
  • Response Summary
  • Evaluation
  • Decision
  • Effect on the Project

At least one interaction must demonstrate that you challenged, corrected, substantially revised, or rejected part of an AI response.

Do not enter confidential, private, or personally identifiable information into an AI system.

 

Submission Requirements

Submit one document containing:

  1. Risk Management Plan
  2. Management Summary
  3. References
  4. AI Prompt and Evaluation Log appendix (Turn in separately)

Use APA 7th edition formatting for citations and references.

 

Length

The Project 1 written analysis should be approximately 4–6 double-spaced pages, using 12-point font and standard 1-inch margins.

The following are not included in the 4–6 page limit:

  • Title page
  • References
  • AI Prompt and Evaluation Log (Turn in separately)
  •  

Quality of analysis is more important than filling the maximum number of pages. Concise, scenario-specific analysis is preferred over unnecessary background information or lengthy general descriptions of cybersecurity.

 

How This Project Leads into Project 2

Project 1 establishes SCHN’s risk management foundation. You will have considered the organization’s context, scope, stakeholders, compliance responsibilities, general risk environment, resources, and broad categories of assets and activities.

 

In Project 2: Identifying Assets and Activities to Be Protected, you will build on this foundation by examining SCHN’s assets and business activities in greater detail.

You will determine what requires protection, why it is important to SCHN, what organizational activities depend on it, and how different assets and activities support the organization’s mission and operations.

The preliminary asset and activity categories identified in Project 1 will provide a starting point for Project 2. You should be prepared to reconsider or revise your earlier assumptions as additional scenario information is introduced.

 

Project 1 establishes the risk management foundation. Project 2 begins the more detailed analysis of what SCHN must protect.

 

Project 2

AI Prompt and Evaluation Log

Include an AI Prompt and Evaluation Log based on your project.

You must document at least three meaningful AI interactions that contributed to your work.

The three interactions should demonstrate the development of your analysis rather than four slightly different versions of the same prompt.

 

At least one interaction must demonstrate that you challenged, corrected, substantially revised, or rejected part of an AI response.

 

For each interaction, complete the following information:

      Item

What to Include

       Purpose

Explain what you were trying to accomplish with the
AI interaction.

      Complete
Prompt

Enter the complete prompt exactly as submitted to the
AI tool.

      Response
Summary

Briefly summarize the major points or recommendations
produced by AI. Do not copy the entire AI response.

      Evaluation

Identify what was useful, inaccurate, incomplete,
unsupported, overly general, unrealistic, or inconsistent with the SCHN
scenario or assigned course materials.

      Decision

Explain what you accepted, changed, rejected,
verified, or investigated further.

      Effect on the
Project

Explain how the interaction influenced your analysis,
decisions, or final submission.

Expectations for the Prompt Log

A strong prompt log should show progression in your thinking.

For example, an interaction might cause you to:

·        Change an assumption

·        Ask a more focused question

·        Investigate an issue further

·        Reject a recommendation

·        Reconsider the priority of a risk

·        Compare alternatives

·        Locate supporting evidence

·        Revise part of your analysis

 

Simply asking AI to “write Project 1” and then documenting the response does not demonstrate appropriate use of AI for this assignment.

 

Your evaluation of the AI response is more important than the sophistication of the prompt itself.

 

Use this document as a template:

For each interaction, complete the following information:

Item

What to Include

 Purpose

Explain what you were trying to accomplish with the AI
interaction.

Complete Prompt

Enter the complete prompt exactly as submitted to the AI
tool.

Response Summary

Briefly summarize the major points or recommendations
produced by AI. Do not copy the entire AI response.

Evaluation

Identify what was useful, inaccurate, incomplete,
unsupported, overly general, unrealistic, or inconsistent with the SCHN
scenario or assigned course materials.

Decision

Explain what you accepted, changed, rejected, verified, or
investigated further.

Effect on the Project

Explain how the interaction influenced your analysis,
decisions, or final submission.