Romyr DelRosario
3-2 Milestone One: Draft of Risk Analysis
IT - 412 Cyberlaw and Ethics
Southern New Hampshire University
Information Technology Structure
The small startup ABC Healthcare company consists of 50 employees who are looking to
expand and grow in the future. The company initially has a very basic layout in the office with
everyone basically operating in one room. Patient files along with HR/Management files are all
stored in the same vicinity of each other. There are several issues that need to be addressed with
how the office is setup now. The network infrastructure is also needing to be audited since the
initial implementation of it there seems to be several issues as well with security concerns of
both users and administrators.
The first issues that would need to be tackled would be the whole layout of the company
office structure. The current structure of the office has all four departments in a single office
space with cubicles separating each user. There are valid complaints from employees that they
can hear each other during the workday. There needs to be a clear line of separation of duties
that the different departments of the company need to operate independently of each other.
Health records of patients can't be compromised and need to be in a secure location along with
employee records. The need to have separate rooms for each department is paramount to
keeping sensitive/personal information secure and private, this also eliminates the problem of
employees hearing each other in the office.
The next concern is the IT/infrastructure layout of the company. The actual datacenter
where the servers reside will need to be in a secure room that only IT personnel will have access
to. The company will also need to enact the policy of multifactor authentication for their user
accounts on the network. Currently they are all using generic usernames and passwords. This is
a grave security liability especially for a healthcare company. Using secure methods of logging
into the company network is priority. I would also setup a secure firewall that sits behind the
2
router that will secure internet traffic coming into either the company website or just the
company network as a whole. The wireless network needs to be secured as well as to not allow
anyone not associated with the company access to the network. The policy of users bringing in
personal equipment either needs to be securely vetted by IT with certain antivirus/malware
software or the use of personal computers/laptops are to be prohibited from being connected to
the company network. The copy machine will need to have the ability to have users print
securely since most documents will be of a sensitive nature and secure printing will give the
users the ability to put a password in at the copier before it prints the document. Another
concern is of the video surveillance of employees without their consent or knowledge. This will
need to also be made transparent and put into policy of th