MAKE SURE to use project templates attached to the post

Paper counts exclusing introduction and references

10 Pages minimum maximum of 15 pages

Topics for Risk Management Research Paper and Presentation

The majority of the paper MUST address the highlighted topic below as it relates to Information Security Risk Management. Specific hardware, software, service or systems may be used as short examples but should only represent a small portion of the total paper.

Select one or both of the following topics

1. InfoSec Disaster Recovery Plans, Business Continuity Plans and Continuity of Operations Plans

2. How Analytics is used in Information Security Risk Management

This research paper should include approximately 7-10 Cited Works but MUST have at least 5 Cited Works of which 4 must be

Peer Reviewed. Highlight in YELLOW the Peer-Reviewed works on the Reference page. Also, include all References as the last page of the Powerpoint Presentation (start by creating a heading called “Peer-Reviewed works”, followed by the Peer- Reviewed works. Then create a heading called “All Other works”, followed by the other works).

This research paper should be approximately 15 pages Maximum double-spaced pages (but must be at least 10 pages), using 12-font Times-Roman or Calibri-Body. The Cover Page, Reference Page and any space needed for pictures/images are not included in the required pages.

Once the paper is completed, add an Overview/Executive Summary to the start of the paper. The Overview must contain at least one Hypothesis (see Rubric) and a Synopsis of what is contained in the paper. Include the Hypothesis, under the title, on the 1stpage of the Powerpoint presentation.

For this paper, a Hypothesis is a statement you believe to be true based on the research you conducted. As an example:

“Small businesses are less likely to provide adequate physical security”.

The quality and thoroughness of the paper, as defined in the rubric, will determine the grade assigned. Papers containing the minimum number of references and/or minimum number of pages will most likely not earn a high grade.

Research Project Rubric Component Project Overview Justification for Hypotheses Supporting Evidence Review of Relevant Research Maintains Purpose / Focus     Methodology Sample Procedures Measures Data analytic plan Grammar, Clarity, and Organization References and Citations Exemplary (3) Effectively and insightfully develops a set of testable, supportable and impactful study hypotheses The introduction section provides a cogent overview of conceptual and theoretical issues related to the study hypotheses. Demonstrates outstanding critical thinking. Adequate (2) Develops a set of testable and supportable hypotheses Inadequate (1) Hypotheses are not testable or justifiable The introduction section provides a logical overview of conceptual and theoretical issues related to the study hypotheses. Demonstrates competent critical thinking. Very little support for the conceptual and theoretical relevant to the study hypotheses was provided. Provides little evidence of sound critical thinking. Provides clearly appropriate evidence to support position Sophisticated integration, synthesis, and critique of literature from related fields. Places work within larger context. Provides adequate evidence to support position Provides a meaningful summary of the literature. Shows understanding of relevant literature. The project has an organizational structure and the focus is clear throughout Identifies appropriate methodologies and research techniques but some details are missing or vague Provides little or no evidence to support position Provides little or no relevant scholarship The project is well organized and has a tight and cohesive focus that is integrated throughout the document Identifies appropriate methodologies and research techniques (e.g., justifies the sample, procedures, and measures). Data analytic plan is suitable to test study hypotheses. Provides appropriate justification for controls. Project is feasible The manuscript is well written and ideas are well developed and explained. Sentences and paragraphs are grammatically correct. Uses subheadings appropriately. Properly and explicitly cited. Reference list matches citations. The manuscript effectively communicates ideas. The writing is grammatically correct, but some sections lack clarity. Properly cited. May have a few instances in which proper citations are missing. The document lacks focus or contains major drifts in focus The methodologies described are either not suited or poorly suited to test hypotheses. The methodology is under-developed and/or is not feasible. The manuscript is poorly written and confusing. Ideas are not communicated effectively. The manuscript lacks proper citations or includes no citations 1 Enter the Title of the Research Paper here ISOL ??? - Group # ?? Group Members: Name Name Name Etc Hypothesis: xxxxxxxxxxxxxxxxxxxx  Summarize the Overview here  Summarize each of your main topics as separate slides  Peer Reviewed references: ◦ xxxxxxxxxxx ◦ Xxxxxxxxxxx  Other references: ◦ Xxxxxxxxxxx ◦ xxxxxxxxxxx ISOL 533 RESIDENCY WEEKEND RESEARCH PAPER 1 [ Enter Title of Paper here ] [ Enter Group # and the names {Last, First} of all Group members ] Overview / Executive Summary [Replace this Note and enter an Overview here. The overview should be added after the content of the paper is completed. The overview should be approximately one paragraph of between 150 and 250 words and summarize the content of the paper. You must add 1-or-more Hypothesis below (in this case, a Hypothesis is a short statement of what your research discovered.] Hypothesis: 1. 2. ISOL 533 RESIDENCY WEEKEND RESEARCH PAPER 2 [Remove this note and enter your paper here. Your paper must be at least 5 pages, 12 font double-spaced and use one inch margins for all paragraphs. The Title page and Reference / Works-Cited pages are NOT included in the 5-page requirement. Any added pictures or images are NOT included in the 5-page requirement. Do not add an Introduction or Abstract since these should be covered in the Overview above. References are added to the last page (consider using the Citations & Bibliography feature in the References tab. To customize a citation, right-click it and then click Edit Citation). There must be at least 5 cited references of which 2 must be peer-reviewed. Highlight in YELLOW the peer-reviewed works on the reference works-cited page. (see example at end of this document) ISOL 533 RESIDENCY WEEKEND RESEARCH PAPER References Last Name, F. M. (Year). Article Title. Journal Title, Pages From - To. Retrieved from url-1 Last Name, F. M. (Year). Book Title. City Name: Publisher Name. City 3 ...
ISOL 533



InfoSec Disaster Recovery Plans, Business Continuity Plans and Continuity of Operations
[Enter Group #
and the names {Last, First} of all Group members]
Overview / Executive Summary
Starting and running a business successfully requires several resources like infrastructure,
staff, and technology. Taking considerations of large organization, they are composed of several
structures and departments that work together to ensure that the organizational goals are
achieved. Most organizations have emphasized on utilization of technology to enhance business
operations. Despite technology being the major core aspect that determines the success of most
businesses today, it could break the organization within the shortest time. Small and large
organizations rely on the internet today, this means that any interference of network would
interfere with major operation areas and operations in the business. Unplanned occurrences that
affect businesses and its operations have necessitated organizations to set up a plan that
guarantees acceptable standards of services during this periods. A well designed business
continuity and disaster recovery plan is going to ensure that these unexpected events are
accommodated without necessarily affecting business operations. This article is going to present
a research for InfoSec Disaster Recovery Plans, Business Continuity Plans and Continuity of
Operations Plans with regards to risk management.

ISOL 533



1. How can organizations enhance the sustainability of their plans?
2. What are some of the approaches that have been taken by the organization’s contingency
to ensure that these information security risks are mitigated?
3. What are some of the best practices to prepare, deploy, and maintain a disaster recovery
and business continuity plan?

There has to be a formal comprehensive description of day-to-day business operations
and security management to enhance business continuity and disaster recovery planning that is
tailored to meet the organizational acceptable standards of service provision. A business
recovery plan is a critical and an essential component with regards to organizational risk
management. “Depending on the nature of the organization and its size and various other factors,
a company must design an optimal plan to minimize the effect of disaster and continue the
critical business functions” (SANS Institute 2002, p. 559). Research shows that nearly one in
every five businesses suffer major interference. Business continuity and business recovery
always serves to ensure that essential functions of business and its operations survive these
disruption. Most articles that have been published regarding disaster recovery and business
continuity with regards to information security have been published while most emphasize on the
general view of business continuity and disaster recovery while none has defined issues and
solutions in a way that can be utilized to manage day-to-day operations for information security.
Most of the publications that exists are expensive hence smaller businesses cannot acquire
considering that their budgets might be limited. The purpose of this article is to bridge this gap.

ISOL 533



Literature Review.
A disaster recovery plan is designed to recover all crucial business process in case of a
disaster within the shortest time possible. It contains all the procedures about how to deal with
emergency situations. Most of the disaster recovery plans are technology oriented methods
whose goal is getting systems up within the shortest time possible. Risk avoidance is the most
recommended strategy to approach disaster recovery.
Business continuity plans entails activities that are required to keep organizational
processes running during interruptions of normal operations. A business continuity plan helps the
organization to provide its services even during the periods of disaster occurrences. With the aid
of this plan, an organizational services shall remain active during the crisis.
It is the responsibility of every individual organization to come up with a plan to counter
the impacts of disaster as a strategy to maintain its competitiveness. Based on the research that
was conducted by Janco Associates in 2016, it indicates that only 5% of the organizations are
adequately prepared for disasters.
Information security and disaster recovery plans determines the ability of a business to
survive. Based on the Global Benchmark study, at least 73% of the organizations lack disaster
recovery strategies. The report also states that more than 5 million losses are incurred as a result
of data center outages, critical application failure, and data losses among others (Kahan, 2014).
According to the Economist, there are massive losses incurred by organizations that are caused
by natural calamities. The figure 1 above shows the amount of losses that companies have
incurred as a result of natural disasters.

ISOL 533



