Write My Paper Button

WhatsApp Widget

Write My Paper Button

WhatsApp Widget

Scenario: You are one of three Information Security Privacy Compliance Officers for the California Tax Agency, which processes individual and business tax returns. You are informed by the Information Security Officer (ISO)

Case Scenario 3: The Security Plan Read the scenario, and then write a paper that responds to the questions posed. Follow the instructions and submission requirements carefully.

Scenario: You are one of three Information Security Privacy Compliance Officers for the California Tax Agency, which processes individual and business tax returns. You are informed by the Information Security Officer (ISO) that a malicious outsider (a “bad actor”) has compromised the agency’s online web-application portal. This portal is responsible for assisting taxpayers with setting up payment plans for their state taxes.

The online web application portal collects:

taxpayer name address social security number date of birth bank account or credit-card payment information During the investigation by the California Highway Patrol and the Computer Investigations Team, it was determined that 2,500 individual taxpayers’ data were obtained from an encrypted Oracle database. The obtained data was encrypted using Transparent Data Encryption (TDE).

California law requires all state agencies to notify California residents whose unencrypted personal information was found to be acquired by bad actors or was believed to have been acquired. You are asked to take the lead in creating a draft of a security plan that addresses organizational needs to prevent future breaches.

Instructions: To begin the security plan, the ISO has asked you to respond to the following prompts:

Following the seven issues that every security plan includes (per Chapter 10 of your textbook), the ISO would like you to address all seven issues, briefly, as a starting point in the building of a security plan. The ISO would also like you to begin the discussion of a Business Continuity Plan (BCP), to ensure the agency can still function in accepting payments during or after an attack. Discuss at least two points that should be considered in this plan and why they should be considered. The agency does not have a clearly defined Incident Response (IR) team to address cyber issues. The ISO is now required to develop this team. To begin the security plan, the ISO has asked you to provide them with the following information: Explain the importance of three aspects that need to be a part of this newly developed response team. Provide a recommendation of what positions should make up this team. Requirements: Address all the above prompts in a 4- to 6-page paper that follows APA 7 style. Include credible sources. Refrain from relying on blogs as sources. To find credible sources, you might begin with the UMGC Library using OneSearch. You can also utilize Google Scholar, a general web search (Google), government websites, and professional organizations. Include a references page for the sources you used. Submission: Review the Grading Rubric to understand how you will be assessed on this assignment.