Need Help with this Question or something similar to this? We got you! Just fill out the order form (follow the link below), and your paper will be assigned to an expert to help you ASAP.
Question Description
Learning Objectives and Outcomes
Develop a plan to deploy public key infrastructure (PKI) and encryption solutions to protect data and information.
Assignment Requirements
Inthis assignment, you play the role of chief information technology (IT)security officer for the Quality Medical Company (QMC). QMC is apublicly traded company operating in the pharmaceutical industry.
QMCis expanding its arena of work through an increase in the number ofclients and products. The senior management of the company is highlyconcerned about complying with the multitude of legislative andregulatory laws and issues in place. The company has an internalcompliance and risk management team to take care of all thecompliance-related issues. The company needs to make important decisionsabout the bulk of resources they will need to meet the voluminouscompliance requirements arising from the multidimensional challenge ofexpansion.
QMC will be required to conform to the following compliance issues:
Public-company regulations, such as the Sarbanes-Oxley (SOX) Act
Regulationsaffecting financial companies, companies that make loans and chargeinterest, such as the U.S. Securities and Exchange Commission (SEC)rules and Gramm-Leach-Bliley Act (GLBA)
Regulations affecting healthcare privacy information, such as Health Insurance Portability and Accountability Act (HIPAA)
IntellectualProperty Law that is important for information asset protectionparticularly for organizations in the pharmaceutical and technologyindustry
Regulations affecting the privacy of information,including personal identification information, such as personallyidentifiable information (PII) regularly collected from employees,customers, and end users
Corporate governance policies includingdisclosures to the board of directors and the auditors and the policiesrelated to human resources, governance, harassment, code of conduct,and ethics
Compliance with regulatory requirements impliesencrypting sensitive data at rest (DAR) and allowing access torole-holders in the enterprise who require the access. It also impliesthat sensitive data in motion (DIM) or data that is being communicatedvia e-mail, instant message (IM), or even Web e-mail must be suitablyprotected and sent only to the individuals who have a right to view it.The company is conscious about the loss they may face in terms ofpenalty and brand damage if they fail to abide by the compliance laws,especially in the online information transfer phase. Therefore, as adedicated employee, your task is to develop a content monitoringstrategy using PKI as a potential solution. You will need to determine aprocess or method to identify multiple data types, processes, andorganizational policies. Incorporate them into a plan, and select a PKIsolution that will effectively address the content management needs ofyour company.
You need to present your PKI solution in the form of a professional report to the senior management.
Required Resources
None
Submission Requirements
Format: Microsoft Word
Font: Arial, 12-Point, Double-Space
Citation Style: APA
Length: 1–2 pages
Self-Assessment Checklist
Use the following checklist to support your work on the assignment:
I have identified specific data types related to the specific compliance regulatory requirements.
I have indicated a solution for sharing data beyond the borders of the organization.
I have appropriately selected and developed a PKI solution for content control.
I have followed the submission requirements.
