Write My Paper Button

WhatsApp Widget

Write My Paper Button

WhatsApp Widget

Your goal is to determine which identified risks present the greatest concern to SCHN based on their likelihood and potential impact. You will not calculate financial loss estimates or numerical risk scores.

Purpose

In the previous projects, you developed a risk management foundation for the Sabine Coastal Health Network (SCHN), identified important assets and business activities, and analyzed threats, vulnerabilities, and potential exploits.

In Project 4, you will use that work to conduct a qualitative risk assessment.

Your goal is to determine which identified risks present the greatest concern to SCHN based on their likelihood and potential impact.

You will not calculate financial loss estimates or numerical risk scores. Instead, you will use defined qualitative categories, organizational evidence, and professional judgment to evaluate and prioritize risk.

The results of this assessment will become the starting point for Project 5: Turning a Risk Assessment into a Risk Mitigation Plan.

Required Course Sources

Your analysis should be based primarily on the assigned textbook.

Primary Sources – Textbook

Managing Risk in Information Systems, 3rd Edition

Chapter 5 – Defining Risk Assessment Approaches

Chapter 5 should provide the primary foundation for:

Purpose of a risk assessment Scope of a risk assessment Critical areas Qualitative versus quantitative approaches Risk assessment challenges Resource and data limitations Estimating impact Using assessment results to support resource allocation and risk acceptance Chapter 6 – Performing a Risk Assessment

Chapter 6 should provide the primary foundation for actually conducting the assessment, including:

Selecting an assessment methodology Reviewing previous findings Identifying relevant assets and activities Evaluating threats Evaluating vulnerabilities Considering existing and planned controls Performing qualitative analysis Developing conclusions Presenting risk assessment results Chapter 8 – Identifying and Analyzing Threats, Vulnerabilities, and Exploits

Use Chapter 8 to support and verify the threat and vulnerability analysis you developed in Project 3.

Project 4 should build upon Project 3 rather than recreate it.

Secondary Sources – NIST Guidance

The textbook is the primary authority for this assignment.

The following NIST publications may be used as secondary sources to strengthen or clarify your analysis.

NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments

This is the most directly relevant NIST publication for Project 4.

It may be used to support concepts involving:

Preparing for a risk assessment Threats and vulnerabilities Likelihood Impact Existing controls Qualitative risk assessment Determining risk Communicating assessment results NIST SP 800-37 Rev. 2 – Risk Management Framework for Information Systems and Organizations

Use this publication primarily to understand how the risk assessment fits within the broader NIST Risk Management Framework (RMF).

The risk assessment performed in this project helps SCHN make better risk-based decisions as it moves toward selecting and implementing responses to identified risks.

NIST SP 800-39 – Managing Information Security Risk: Organization, Mission, and Information System View

This publication may be used when considering how cybersecurity risks affect:

Organizational operations Mission and business functions Organizational assets Individuals Reputation Management decision-making Source Priority

For this project:

Textbook Chapters 5, 6, and 8 = Primary Sources

NIST Publications = Secondary Supporting Sources

Students are not expected to reproduce the complete NIST risk assessment methodology.

Use NIST to support and strengthen the concepts learned in the textbook.

Scenario Update

SCHN leadership has completed a midyear review of its financial and cybersecurity position.

Several conditions now affect cybersecurity decision-making:

Operating expenses have increased. SCHN continues to operate with limited cybersecurity personnel and financial resources. Management cannot address every identified cybersecurity risk at the same time. SCHN has some historical incident information, but it does not have sufficiently reliable historical loss, frequency, or cost data to support a defensible quantitative risk assessment. Executive management needs a practical way to determine which cybersecurity risks deserve the greatest immediate attention. Because reliable quantitative data are limited, management has directed the cybersecurity team to perform a qualitative risk assessment.

Leadership wants the assessment to:

Use a consistent approach. Evaluate both likelihood and impact. Consider SCHN’s actual organizational conditions. Account for existing controls where known. Clearly distinguish higher-priority risks from lower-priority risks. Identify the three risks that should move forward into formal risk mitigation planning. You are the cybersecurity analyst responsible for conducting this assessment.

Your Assignment

Using the SCHN scenario and the work completed in Projects 1, 2, and 3, conduct a qualitative risk assessment of the organization.

You must assess at least six significant risks.

Your assessment should demonstrate the progression from:

Asset or Business Activity → Threat → Vulnerability → Organizational Risk → Likelihood → Impact → Risk Level → Priority

Do not restart the analysis from the beginning.