The world’s Largest Sharp Brain Virtual Experts Marketplace Just a click Away
Levels Tought:
Elementary,Middle School,High School,College,University,PHD
| Teaching Since: | Apr 2017 |
| Last Sign in: | 103 Weeks Ago, 3 Days Ago |
| Questions Answered: | 4870 |
| Tutorials Posted: | 4863 |
MBA IT, Mater in Science and Technology
Devry
Jul-1996 - Jul-2000
Professor
Devry University
Mar-2010 - Oct-2016
Compliance Review and Compilation
Â
Â
Â
Â
Background -Â Company Overview
Â
You have just been hired as Director of Compliance for a large, publicly traded health insurance company named "Green Sword, Purple Armor" (GSPA).
Â
GSPA is a leading health insurance and managed healthcare provider in Illinois and has the following aspects to consider:
Â
Only provides services to Illinois, Wisconsin and Indiana residents.
Offices located in Chicago, Milwaukee, Indianapolis, Springfield (IL) and Schaumburg.
About 1000 employees in Illinois.
Publicly traded on Nasdaq.
Revenue of $2.5 Billions in 2012.
Net profits of $500 Millions in 2012.
Allows its customers to pay for their deductibles via all major credit cards
Â
Â
Assignment
Â
Note: all deliverables should be in word, excel or PDF documents grouped together in a ZIP file on D2L.
Â
Â
Part 1: Determine compliance requirements
Â
Based on the overview presented above, research and document the major laws, regulations or industry standards that GSPA must comply with.
Â
You should be able to identify at least 3 major compliance requirements.
Â
Document these compliance requirements and justify why GSPA need/should comply.
Â
Â
Â
Part 2:Â Security controls requirements table.
Â
Based on the compliance requirements identified in step one, create a table or an XLS spreadsheet that lists all the security controls that you should implement and document the section(s) from the compliance/standards/laws that refer to the control. Also mention if mandatory or optional.
Â
Your table/XLS may look like this:
Â
|
# |
Control Name |
CIP v5 |
French Regulation 123 |
Polar Laws |
Yet Another Industry |
|
1 |
Firewall protect French People |
N/A |
Part 1, paragraph12 Required |
Law #45,b |
N/A |
|
2 |
Encrypt critical data |
CIP xxx page 123 |
NA |
NA |
Page 44 |
|
3 |
...etc... |
 |
 |
 |
 |
Â
Â
Â
Make sure that you group similar controls for different regulations together even if names are different. For example, one compliance requirement would be to "filter packet" while another may refer to "firewall"
Â
Part 3: Explain the controls
Â
For each of the control, write a few lines explaining the controls and how they apply for each regulation
Â
Also if you feel other controls, not required should be in place, please include them here and describe them in more details.
Â
Part 4: Recommendation for Implementation
Â
Please present your plan for implementing these control and prioritize the implementation based on what you think is most critical. Assume that no controls are currently in place.
Â
Justify your prioritization.
-----------