CH6 Risk Management Priorities & Information Security Cost Benefit Analysis Paper

This assignment consists of two parts and you are required to prepare and submit two (2) separate documents as part of this activity.

1. First, using your own organization or one of your choosing, create a listing of assets and their vulnerabilities. Assign a risk-rating value to each of these assets according to the importance of these assets to the organization. Provide a brief summary of this ranking and explain your rationale for prioritizing the assets.

2.Using the risk management prioritization and rating you created in the previous activity, create a cost-benefit analysis. In other words, describe the assets and the cost of these assets as well as the cost of protecting these assets. Include items that affect the cost of a particular risk treatment strategy, including implementing new or improved safeguards under the defense option. Examples include the cost of hardware, software, services, training, installation of software, configuration, testing, vendor fees, maintenance, and cost from the loss of these assets.

