Low Impact System Contingency Plan of Karl Healthcare Organization
Wk 10: Contingency Plan
Imagine you are the Contingency Planning Coordinator at a major Healthcare System. The hospitals have been attacked by Ransomware. Patients and patient data, communications and emergency logistics have been severely impacted. Create a hypothetical organization with details including geographic locations, the number of employees in each location, the primary business functions, and operational and technology details. In the BIA, you will document the potential threats to the business and its technology. Assume this organization is lacking in its contingency planning efforts and requires assistance in creating a plan that addresses technological attacks such as ransomware to increase its overall security and preparedness posture.
Research and review recent cases of hospital system ransomware attacks for Background only.
Write an 8–10 page contingency plan using the provided templates:
* Business Impact Analysis Template [DOCX].
* Low Impact System Contingency Plan Template [DOCX].
1. Provide an overview of the organization, including business type, primary mission functions, and indicate why contingency planning efforts are needed and how these efforts could benefit the business.
2. Create a hypothetical incident scenario where contingency planning efforts would need to be utilized and discuss the use of hot sites, warm sites, and mobile sites for data restoration.
3. Develop a full contingency plan for the organization. Include all subordinate functions or sub-plans, including:
* Business Impact Assessment.
* Incident Response Plan.
* Business Continuity Plan.
* Disaster Recovery Plan.
* Use the templates provided in NIST 800-34 Rev. 1 Appendices to help with your documentation. Website: https://csrc(dot)nist(dot)gov/publications/detail/sp/800-34/rev-1/final
4. Use at least four quality resources for this assignment. Note: Wikipedia and similar websites do not qualify as quality resources.
Project Karl
Security Categorization: Low
Karl Healthcare Organization
Information System Contingency Plan (ISCP)
Version 2
June 13, 2023
Prepared by
Karl Healthcare Organization
123 Main Street
Pasadena, California, 90210
TABLE OF CONTENTS
Plan Approval…………………………………………………….………..….……….……A.1-3
1. Introduction ………………………………………………….……..……….…….……..A.1-4
1.1 Background………..………………………………………….………………..A.1-4
1.2 Scope……..………..…………………………..…….……….……….………..A.1-4
1.3 Assumptions..…….………………………..….……………….……….……...A.1-4
2. Concept of Operations ………………………….……..…………………………..……A.1-5
2.1 System Description………………....……………………………………..…..A.1-5
2.2 Overview of Three Phases..…………………………………………………..A.1-5
2.3 Roles and Responsibilities…….…......……………………………………....A.1-5
3. Activation and Notification………………....………………………..………….……..A.1-6
3.1 Activation Criteria and Procedure ...………………………..………………..A.1-6
3.2 Notification…………………...………………………………..………………..A.1-6
3.3 Outage Assessment…………....…......……………………..………………..A.1-6
4. Recovery……………………….……………....…………………………………………..A.1-7
4.1 Sequence of Recovery Activities ....……………………………..…………..A.1-7
4.2 Recovery Procedures ……...………………………………………..………..A.1-8
4.3 Recovery Escalation Notices/Awareness..……………………………..……A.1-8
5. Reconstitution..……………….……………....………………….………………..……..A.1-8
5.1 Validation Data Testing………...…………………….…….….………….…..A.1-8
5.2 Validation Functionality Testing…........…………….……..…………….…...A.1-8
5.3 Recovery Declaration…………........………………….………………….…..A.1-8
5.4 Notification (users)…. ……...………………………….………………….…..A.1-8
5.5 Cleanup ...……………………...…......……………….………………….……A.1-8
5.6 Data Backup………………...………………………….…………………..…..A.1-8
5.7 Event Documentation…………..…......……………….………………….…..A.1-9
5.8 Deactivation……………………..…......……………….………………….…..A.1-9
References 1. Introduction
Information systems are vital to Karl Healthcare Organization’s mission/business processes; therefore, it is critical that services provided by Karl Healthcare System are able to operate effectively without excessive interruption. This Information System Contingency Plan (ISCP) establishes comprehensive procedures to recover Karl Healthcare System quickly and effectively following a service disruption. 1.1 Background This Karl Healthcare System ISCP establishes procedures to recover Karl Healthcare System following a disruption. The following recovery plan objectives have been established:
- Maximize the effectiveness of contingency operations through an established plan that consists of the following phases:
- Activation and Notification phase to activate the plan and determine the extent of damage;
- Recovery phase to restore Karl Healthcare System operations; and
- Reconstitution phase to ensure that Karl Healthcare System is validated through testing and that normal operations are resumed.
- Identify the activities, resources, and procedures to carry out Karl Healthcare System processing requirements during prolonged interruptions to normal operations.
- Assign responsibilities to designated Karl Healthcare Organization personnel and provide guidance for recovering Karl Healthcare System during prolonged periods of interruption to normal operations.
- Ensure coordination with other personnel responsible for Karl Healthcare Organization contingency planning strategies. Ensure coordination with external points of contact and vendors associated with Karl Healthcare System and execution of this plan.
- Karl Healthcare System has been established as a low-impact system, in accordance with FIPS 199.
- Alternate processing sites and offsite storage are not required for this system.
- The Karl Healthcare System is inoperable and cannot be recovered within 24 hours
- Key Karl Healthcare System personnel have been identified and trained in their emergency response and recovery roles; they are available to activate the Karl Healthcare System Contingency Plan.
The Karl Healthcare System ISCP does not apply to the following situations:
- Overall recovery and continuity of mission/business operations. The Business Continuity Plan (BCP) and Continuity of Operations Plan (COOP) address continuity of mission/business operations.
- Emergency evacuation of personnel. The Occupant Emergency Plan (OEP) addresses employee evacuation.
- Regulatory compliance. The ISCP will adhere to any laws and regulations while carrying out recovery
- Appropriate training: staff will be adequately trained to ensure they are highly skilled when it comes to implementing the plan.
👀 Other Visitors are Viewing These APA Essay Samples:
-
Strategic Communication at Research In Motion (RIM)
3 pages/≈825 words | 3 Sources | APA | Management | Term Paper |
-
Internal Communication
5 pages/≈1375 words | 3 Sources | APA | Management | Term Paper |
-
Creation of a Strategic Communication Case Study
12 pages/≈3300 words | 2 Sources | APA | Management | Term Paper |