Question: Read the Midwest Health System: Information System Risks and Control Case Study and use the knowledge and learnings gained on IT Risk Management during the
Read the Midwest Health System: Information System Risks and Control Case Study and use the knowledge and learnings gained on IT Risk Management during the trimester to answer the following questions: Question 1- Business Understanding Based on the information provided, write a short summary of your understanding of the business. Question 2- IT Risk Identification Based on the information provided in the case study, identify five risks by providing the risk event, cause/sources, and the impact/consequence (the bowtie method). Question 3- IT Risk analysis and evaluation Define a scale that can be used to determine the inherent and residual risks, and a scale that can be used to determine the effectiveness and adequacy of the controls. Use the defined scales to assess the inherent risk, current control effectiveness and adequacy, and residual risk (based on current controls) of the risks identified in Question 2. Question 4- IT Risk treatment Provide additional controls for the identified residual risks with a treatment plan (avoid, mitigate, monitor, transfer, accept), and based on the additional controls, the new residual risk. Question 5- Risk appetite Based on the risk case study, and the risk assessment that you have done, define MidWest Healths risk appetite focusing on the risks that you have identified. Question 6- IT Risk communication Provide the CIO (Steve Nelson) with a recommendation, based on the risk assessment, treatment plan and appetite, on how to further strengthen MidWest Health Systems risk management framework and ultimately enhancing resilience and efficiency.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
