Question Scenario HISI is a new company (3 years) with slightly over 250… ScenarioHISI is a new company (3 years) wi

Question Scenario HISI is a new company (3 years) with slightly over 250… ScenarioHISI is a new company (3 years) with slightly over 250 workers and yearly revenue of $100 million, as mentioned in the scenario. The company has a headquarters outside of Richmond, Virginia and an additional site near San Diego, California which supports a mix of company operations. For its corporate IT infrastructure, the corporation uses a managed services infrastructure, relying on a combination of major cloud infrastructure and services providers (aside from the company laptops and smartphones provided to all staff and executives). This covers traditional telecom and corporate desktop services, as well as IT production and development environments, databases, and internet presence (e-mail, document processing, reports management, etc.). SecureConnect, SecureExchange, and SecurePay are the three main services provided by HISI. SecureConnect is an online directory that allows clients to find doctors, clinics, and other medical institutions in their area. It includes information about doctors’ specialties, practice locations, medical qualifications, and the services that the doctors’ practices and clinics provide. Managers of practices and clinics are granted credentials and have the ability to alter their profiles. Customers of HISI, mostly hospitals and clinics, use HTTPS connections to access all three of the company’s products. Patients can also make payments through HTTPS websites that are accessible over the Internet. SecureExchange is a secure medical messaging service that is the company’s main source of revenue. It receives communications from its customers, such as large clinics, and securely routes them to recipients, such as hospitals or other clinics. Many of the firm’s customers use SecurePay, an online platform that helps them manage secure billing and payments. The cloud-based interface allows a variety of payment methods and communicates with credit card processing companies. Alyssa is a recently hired cybersecurity risk manager for a fictitious health services organization, Health Infrastructure Services, Inc. The CISO has determined that the existing risk management plan is out of date and a new risk management plan must be developed. Senior leadership is committed to and supportive of the project to develop a new plan. Threats Identified: Upon review of the current risk management plan, the following threats were identified:Loss of company data due to cloud services and infrastructureLoss of company information on lost or stolen company-owned assets, such as mobile phones and laptopsLoss of customers due to production outages caused by various events, such as natural disasters, change management, unstable software, and so onRemote access threatsInsider threatsChanges in regulatory landscape that may impact operationsHer senior management told her that the risk assessment approach/plan and defined/illustrated process should specifically include:What would an outline of the risk assessment plan for this scenario look like?.What would an introduction to the plan explaining its purpose and importance be?.What should the defined scope and boundaries for the plan be?What would a summary of planned risk assessment approach(es) to be used look like for this scenario?Who would be the key stakeholder roles and responsibilities (individuals and departments) related to risk assessment of this organization?How would a proposed schedule for the risk assessment process for this organization look like?  Computer Science Engineering & Technology Information Security CYB 421 Share QuestionEmailCopy link