erm Paper: Managing an IT Infrastructure Audit
Due Week 10 and worth 210 points
This assignment consists of four (4) sections: an internal IT
audit policy, a management plan, a project plan, and a disaster
recovery plan.
You must submit all four (4) sections as separate files for the
completion of this assignment.
Label each file name according to the section of the assignment
it is written for. Additionally, you may create and /or assume all
necessary assumptions needed for the completion of this
assignment.
Imagine you are an Information Security Manager for a large
national retailer. You have been hired to be directly responsible
for the planning and oversight of IT audits. At the request of the
Board of Directors, the CEO has tasked you with developing a
plan for conducting regular audits of the IT infrastructure. The
planning and management aspects of IT audit are critical to the
overall success of the audit, and as a result, the overall success
of the systems implemented within the organization. You must
develop a policy for conducting IT audits and develop a project
plan for conducting two week IT audits.
In addition to the typical networking and Internetworking
infrastructure of a medium-sized organization, the organization
has the following characteristics:
They have a main office and 268 stores in the U.S.
They utilize a cloud computing environment for storage and
applications.
Their IT infrastructure includes Cisco workgroup and core
switches, Cisco routers, Cisco firewalls and intrusion
prevention systems, and servers running Microsoft Windows
Server 2012.
They have over 1000 desktops and approximately 500
organization-owned laptops in the main headquarters.
They allow employees to bring their own devices into the
organization; however, they are subject to being searched upon
entry and exit from the building.
They enable remote access to corporate information assets for
employees and limited access to extranet resources for
contractors and other business partners.
They enable wireless access at the main office and the stores.
They process an average of 67.2 credit card transactions per
hour every day at each location and via their corporate Website.
Section 1: Internal IT Audit Policy
Write a three to four (3-4) page paper in which you:
1. Develop an Internal IT Audit Policy, which includes at a
minimum:
a. Overview
b. Scope
c. Goals and objectives
d. Compliance with applicable laws and regulations
e. Management oversight and responsibility
f. Areas covered in the IT audits
g. Frequency of the audits
h. Use at least two (2) quality resources in this assignment.
Note
: Wikipedia and similar Websites do not qualify as quality
resources.
Section 2: Management Plan
Write a four to six (4-6) page paper in which you:
2. Explain the management plan for conducting IT audits,
including:
a. Risk management
b. System Software and Applications
c. Wireless Networking
d. Cloud Computing
e. Virtualization
f. Cybersecurity and Privacy
g. BCP and DRP
h. Network Security
i. Use at least three (3) quality resources in this assignment.
Note
: Wikipedia and similar Websites do not qualify as quality
resources.
Section 3: Project Plan
Use Microsoft Project or an Open Source alternative, such as
Open Project to:
3. Develop a project plan which includes the applicable tasks
for each of the major areas listed below for each element of the
IT audit mentioned above; plan for the audit to be a two (2)
week audit.
a. Risk management
b. System software and applications
c. Wireless networking
d. Cloud computing
e. Virtualization
f. Cybersecurity and privacy
g. Network security
Section 4: Disaster Recovery Plan
Write a five to seven (5-7) page paper in which you:
4. Develop a disaster recovery plan (DRP) for recovering
from a major incident or disaster affecting the organization.
a. The organization must have no data loss.
b. The organization must have immediate access to
organizational data in the event of a disaster.
c. The organization must have critical systems operational
within 48 hours.
d. Include within the DRP the audit activities needed to
ensure that the organization has an effective DRP and will be
able to meet the requirements stated above.
e. Use at least three (3) quality resources in this assignment.
Note
: Wikipedia and similar Websites do not qualify as quality
resources.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size
12), with one-inch margins on all sides; citations and references
must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the
student’s name, the professor’s name, the course title, and the
date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this
assignment are:
Describe the Sarbanes-Oxley (SOX) act and Committee of
Sponsoring Organizations (COSO) framework.
Describe the process of performing effective information
technology audits and general controls.
Describe the various general controls and audit approaches for
software and architecture to include operating systems,
telecommunication networks, cloud computing, service-oriented
architecture and virtualization.
Explain the role of cybersecurity privacy controls in the review
of system processes.
Discuss and develop strategies that detect and prevent
fraudulent business practices.
Describe and create an information technology disaster recovery
plan.
Develop an audit plan and control framework that addresses and
solves a proposed business problem.
Use technology and information resources to research issues in
information technology audit and control.
Write clearly and concisely about topics related to information
technology audit and control using proper writing mechanics
and technical style conventions.
Click
here
to view the grading rubric for this assignment.
erm Paper Managing an IT Infrastructure AuditDue Week 10 and wo

More Related Content

DOCX
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docx
DOC
Strayer cis 558 week 10 term paper managing an it infrastructure audit
DOC
Strayer cis 558 week 10 term paper managing an it infrastructure audit
DOC
Strayer cis 558 week 10 term paper managing an it infrastructure audit
DOC
Strayer cis 558 week 10 term paper managing an it infrastructure audit
DOCX
Case Study 1 Mitigating Cloud Computing RisksDue Week 4 and wor
DOC
Strayer cis 349 week 10 term paper planning an it infrastructure audit for co...
DOCX
Planning an IT Infrastructure Audit for ComplianceThe audit planni.docx
Term Paper Managing an IT Infrastructure AuditDue Week 10 a.docx
Strayer cis 558 week 10 term paper managing an it infrastructure audit
Strayer cis 558 week 10 term paper managing an it infrastructure audit
Strayer cis 558 week 10 term paper managing an it infrastructure audit
Strayer cis 558 week 10 term paper managing an it infrastructure audit
Case Study 1 Mitigating Cloud Computing RisksDue Week 4 and wor
Strayer cis 349 week 10 term paper planning an it infrastructure audit for co...
Planning an IT Infrastructure Audit for ComplianceThe audit planni.docx

Similar to erm Paper Managing an IT Infrastructure AuditDue Week 10 and wo (20)

DOCX
Term Paper Planning an IT Infrastructure Audit for Compliance  Due .docx
DOCX
CIS 558 Inspiring Innovation/tutorialrank.com
DOCX
CIS 558 RANK Inspiring Innovation--cis558rank.com
PDF
CIS 558 RANK Education Counseling--cis558rank.com
PDF
CIS 558 RANK Education Planning--cis558rank.com
DOCX
CIS 558 RANK Lessons in Excellence--cis558rank.com
DOC
Cis 558 Education Specialist-snaptutorial.com
DOCX
CIS 558 Education Organization / snaptutorial.com
PDF
CIS 558 Effective Communication - tutorialrank.com
DOCX
CIS 558 Success Begins / snaptutorial.com
DOCX
Cis 558 Technology levels--snaptutorial.com
DOCX
Cis 558 Enthusiastic Study / snaptutorial.com
DOCX
Note Chapter 5 of the required textbook may be helpful in the com.docx
DOCX
CIS 558 Entire Course NEW
DOCX
The Rookie Chief Information Security OfficerWorth 200 poi
DOC
Uop cis 349 week 10 term paper planning an it infrastructure audit for compli...
DOC
Cis 349 week 10 term paper planning an it infrastructure audit for compliance
DOC
Uop cis 349 week 10 term paper planning an it infrastructure audit for compli...
DOCX
CIS 558 Enhance teaching / snaptutorial.com
DOC
Uop cis 349 week 10 term paper planning an it infrastructure audit for compli...
Term Paper Planning an IT Infrastructure Audit for Compliance  Due .docx
CIS 558 Inspiring Innovation/tutorialrank.com
CIS 558 RANK Inspiring Innovation--cis558rank.com
CIS 558 RANK Education Counseling--cis558rank.com
CIS 558 RANK Education Planning--cis558rank.com
CIS 558 RANK Lessons in Excellence--cis558rank.com
Cis 558 Education Specialist-snaptutorial.com
CIS 558 Education Organization / snaptutorial.com
CIS 558 Effective Communication - tutorialrank.com
CIS 558 Success Begins / snaptutorial.com
Cis 558 Technology levels--snaptutorial.com
Cis 558 Enthusiastic Study / snaptutorial.com
Note Chapter 5 of the required textbook may be helpful in the com.docx
CIS 558 Entire Course NEW
The Rookie Chief Information Security OfficerWorth 200 poi
Uop cis 349 week 10 term paper planning an it infrastructure audit for compli...
Cis 349 week 10 term paper planning an it infrastructure audit for compliance
Uop cis 349 week 10 term paper planning an it infrastructure audit for compli...
CIS 558 Enhance teaching / snaptutorial.com
Uop cis 349 week 10 term paper planning an it infrastructure audit for compli...

More from eleanorabarrington (20)

DOCX
Employment in U.S.To be employed in the U.S., you must complet.docx
DOCX
Employee Training and Career Development PaperWrite a 1,05.docx
DOCX
Employment-At-Will DoctrineImagine you are a recently-hired .docx
DOCX
Employee Selection Please respond to the followingCompare and c.docx
DOCX
Emerging nations are generally defined as those countries working to.docx
DOCX
Emerging Adulthood and CultureDueJul 12, 1000 PM  CST.docx
DOCX
Eli Lily Case Questions(1page total will be fine)case see attach.docx
DOCX
Encryption in Investigations  Please respond to the following.docx
DOCX
Emerging Trends in Logistics and Supply Chain Management10 pag.docx
DOCX
EN102 Sum15Paper Two ImagesPictures of Significance and What We .docx
DOCX
Ellas father, Frederic has Parkinson disease known as Shaky Grandp.docx
DOCX
ELL Placement Assessments Interview the ELL instructor that you ob.docx
DOCX
eliverable Length1,000–1,250 wordsDetailsWeekly tasks or ass.docx
DOCX
Elements of Projects  Please respond to the followingRese.docx
DOCX
Emotional IntelligencePerform an internet search on emotional inte.docx
DOCX
Employee satisfaction is the product of many factors, some directly .docx
DOCX
Emily is an 18-month-old toddler developing typically. She attends.docx
DOCX
Assignment 4 Designing Compliance within the LAN-to-WAN DomainDue.docx
DOCX
Assignment 4 Contemporary Issues in Modern Police Operations and .docx
DOCX
Assignment 4 Communication MethodsChoose five (5) different commu.docx
Employment in U.S.To be employed in the U.S., you must complet.docx
Employee Training and Career Development PaperWrite a 1,05.docx
Employment-At-Will DoctrineImagine you are a recently-hired .docx
Employee Selection Please respond to the followingCompare and c.docx
Emerging nations are generally defined as those countries working to.docx
Emerging Adulthood and CultureDueJul 12, 1000 PM  CST.docx
Eli Lily Case Questions(1page total will be fine)case see attach.docx
Encryption in Investigations  Please respond to the following.docx
Emerging Trends in Logistics and Supply Chain Management10 pag.docx
EN102 Sum15Paper Two ImagesPictures of Significance and What We .docx
Ellas father, Frederic has Parkinson disease known as Shaky Grandp.docx
ELL Placement Assessments Interview the ELL instructor that you ob.docx
eliverable Length1,000–1,250 wordsDetailsWeekly tasks or ass.docx
Elements of Projects  Please respond to the followingRese.docx
Emotional IntelligencePerform an internet search on emotional inte.docx
Employee satisfaction is the product of many factors, some directly .docx
Emily is an 18-month-old toddler developing typically. She attends.docx
Assignment 4 Designing Compliance within the LAN-to-WAN DomainDue.docx
Assignment 4 Contemporary Issues in Modern Police Operations and .docx
Assignment 4 Communication MethodsChoose five (5) different commu.docx

Recently uploaded (20)

PDF
LDMMIA Reiki Yoga Finals Review Spring Summer
PDF
1.3 FINAL REVISED K-10 PE and Health CG 2023 Grades 4-10 (1).pdf
PDF
Τίμαιος είναι φιλοσοφικός διάλογος του Πλάτωνα
PPTX
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx
PPTX
Onco Emergencies - Spinal cord compression Superior vena cava syndrome Febr...
PDF
OBE - B.A.(HON'S) IN INTERIOR ARCHITECTURE -Ar.MOHIUDDIN.pdf
PPTX
Chinmaya Tiranga Azadi Quiz (Class 7-8 )
PDF
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
PDF
Hazard Identification & Risk Assessment .pdf
PDF
My India Quiz Book_20210205121199924.pdf
PDF
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 1)
PDF
Paper A Mock Exam 9_ Attempt review.pdf.
PDF
CISA (Certified Information Systems Auditor) Domain-Wise Summary.pdf
PPTX
Computer Architecture Input Output Memory.pptx
PPTX
CHAPTER IV. MAN AND BIOSPHERE AND ITS TOTALITY.pptx
PDF
FOISHS ANNUAL IMPLEMENTATION PLAN 2025.pdf
PPTX
A powerpoint presentation on the Revised K-10 Science Shaping Paper
PDF
Empowerment Technology for Senior High School Guide
PDF
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
PDF
International_Financial_Reporting_Standa.pdf
LDMMIA Reiki Yoga Finals Review Spring Summer
1.3 FINAL REVISED K-10 PE and Health CG 2023 Grades 4-10 (1).pdf
Τίμαιος είναι φιλοσοφικός διάλογος του Πλάτωνα
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx
Onco Emergencies - Spinal cord compression Superior vena cava syndrome Febr...
OBE - B.A.(HON'S) IN INTERIOR ARCHITECTURE -Ar.MOHIUDDIN.pdf
Chinmaya Tiranga Azadi Quiz (Class 7-8 )
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
Hazard Identification & Risk Assessment .pdf
My India Quiz Book_20210205121199924.pdf
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 1)
Paper A Mock Exam 9_ Attempt review.pdf.
CISA (Certified Information Systems Auditor) Domain-Wise Summary.pdf
Computer Architecture Input Output Memory.pptx
CHAPTER IV. MAN AND BIOSPHERE AND ITS TOTALITY.pptx
FOISHS ANNUAL IMPLEMENTATION PLAN 2025.pdf
A powerpoint presentation on the Revised K-10 Science Shaping Paper
Empowerment Technology for Senior High School Guide
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
International_Financial_Reporting_Standa.pdf

erm Paper Managing an IT Infrastructure AuditDue Week 10 and wo

  • 1. erm Paper: Managing an IT Infrastructure Audit Due Week 10 and worth 210 points This assignment consists of four (4) sections: an internal IT audit policy, a management plan, a project plan, and a disaster recovery plan. You must submit all four (4) sections as separate files for the completion of this assignment. Label each file name according to the section of the assignment it is written for. Additionally, you may create and /or assume all necessary assumptions needed for the completion of this assignment. Imagine you are an Information Security Manager for a large national retailer. You have been hired to be directly responsible for the planning and oversight of IT audits. At the request of the Board of Directors, the CEO has tasked you with developing a plan for conducting regular audits of the IT infrastructure. The planning and management aspects of IT audit are critical to the overall success of the audit, and as a result, the overall success of the systems implemented within the organization. You must develop a policy for conducting IT audits and develop a project plan for conducting two week IT audits. In addition to the typical networking and Internetworking infrastructure of a medium-sized organization, the organization has the following characteristics: They have a main office and 268 stores in the U.S. They utilize a cloud computing environment for storage and
  • 2. applications. Their IT infrastructure includes Cisco workgroup and core switches, Cisco routers, Cisco firewalls and intrusion prevention systems, and servers running Microsoft Windows Server 2012. They have over 1000 desktops and approximately 500 organization-owned laptops in the main headquarters. They allow employees to bring their own devices into the organization; however, they are subject to being searched upon entry and exit from the building. They enable remote access to corporate information assets for employees and limited access to extranet resources for contractors and other business partners. They enable wireless access at the main office and the stores. They process an average of 67.2 credit card transactions per hour every day at each location and via their corporate Website. Section 1: Internal IT Audit Policy Write a three to four (3-4) page paper in which you: 1. Develop an Internal IT Audit Policy, which includes at a minimum: a. Overview b. Scope c. Goals and objectives
  • 3. d. Compliance with applicable laws and regulations e. Management oversight and responsibility f. Areas covered in the IT audits g. Frequency of the audits h. Use at least two (2) quality resources in this assignment. Note : Wikipedia and similar Websites do not qualify as quality resources. Section 2: Management Plan Write a four to six (4-6) page paper in which you: 2. Explain the management plan for conducting IT audits, including: a. Risk management b. System Software and Applications c. Wireless Networking d. Cloud Computing e. Virtualization f. Cybersecurity and Privacy g. BCP and DRP h. Network Security
  • 4. i. Use at least three (3) quality resources in this assignment. Note : Wikipedia and similar Websites do not qualify as quality resources. Section 3: Project Plan Use Microsoft Project or an Open Source alternative, such as Open Project to: 3. Develop a project plan which includes the applicable tasks for each of the major areas listed below for each element of the IT audit mentioned above; plan for the audit to be a two (2) week audit. a. Risk management b. System software and applications c. Wireless networking d. Cloud computing e. Virtualization f. Cybersecurity and privacy g. Network security Section 4: Disaster Recovery Plan Write a five to seven (5-7) page paper in which you: 4. Develop a disaster recovery plan (DRP) for recovering from a major incident or disaster affecting the organization.
  • 5. a. The organization must have no data loss. b. The organization must have immediate access to organizational data in the event of a disaster. c. The organization must have critical systems operational within 48 hours. d. Include within the DRP the audit activities needed to ensure that the organization has an effective DRP and will be able to meet the requirements stated above. e. Use at least three (3) quality resources in this assignment. Note : Wikipedia and similar Websites do not qualify as quality resources. Your assignment must follow these formatting requirements: Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow APA or school-specific format. Check with your professor for any additional instructions. Include a cover page containing the title of the assignment, the student’s name, the professor’s name, the course title, and the date. The cover page and the reference page are not included in the required assignment page length. The specific course learning outcomes associated with this assignment are:
  • 6. Describe the Sarbanes-Oxley (SOX) act and Committee of Sponsoring Organizations (COSO) framework. Describe the process of performing effective information technology audits and general controls. Describe the various general controls and audit approaches for software and architecture to include operating systems, telecommunication networks, cloud computing, service-oriented architecture and virtualization. Explain the role of cybersecurity privacy controls in the review of system processes. Discuss and develop strategies that detect and prevent fraudulent business practices. Describe and create an information technology disaster recovery plan. Develop an audit plan and control framework that addresses and solves a proposed business problem. Use technology and information resources to research issues in information technology audit and control. Write clearly and concisely about topics related to information technology audit and control using proper writing mechanics and technical style conventions. Click here to view the grading rubric for this assignment.