I chose a large medical organization with multiple hospitals and medical facilities spread across Georgia

Assignment Content

  1. The organization you chose in Week 1 is hosting a National Convention for all the executive staff members from all 25 international locations next week. The CIO requests your team of Risk Management Analyst to create and deliver the presentation on the topic, "Deterministic versus Probabilistic Risk in IT Risk Management." As the representative of your team, you will create and deliver the presentation with an Executive Summary at one of the Executive Round Table Meetings at the convention. Additionally, the CIO stressed you use creativity to make the presentation as interesting as possible.Research information about your chosen organization to complete this week's assignment.Part A:Create a media-rich, 10-slide Microsoft® PowerPoint® presentation. Include the following:
    • Monte Carlo planning analyses
    • Building and running Monte Carlo models
    • The deterministic risk assessment method
    • The probabilistic risk assessment method
    • How does the NIST risk management framework 3-tiers ensure information security (NIST SP 800-53, revision 4)?
    • How are data and information systems categorized?
    • Do not use research quotes or acronyms. You must use your own words.
    Part B: Create a 1- to 2-page Microsoft® Word Executive Summary on this presentation. Include the following:
    • Goals and objectives of the presentation in summary form
    • Adequate references to support your findings, information, and opinions
    Note: Media-rich presentations should include multimedia such as graphics, pictures, video clips, or audio.Include APA-formatted citations when necessary.Submit your assignment.

IT Risk Management
Categorization of Data and Information
• Systems
• Electronic Medical Record
• Master Patient Ind0ex
• Clinical Decision Support

• Data
• Health surveys
• Claims data
• Administrative data

Deterministic versus Probabilistic Risk
• Deterministic
-Analyses the risk using the impact of a
single risk scenario
• Probabilistic Risk
-Uses all possible scenarios;
• Likelihood
• And impacts

Deterministic Risk Analysis
• Medical Risks

System Failure
Natural Disaster
Malicious attacks

Accidental Human interference

… Deterministic method

Probabilistic Risk Analysis

Monte Carlo Simulation

Building Monte Carlo Models
• System Failure due to malicious attacks
• 20% chance of malicious attack
• 30% change of no malicious attack
• 40% chance of early recognition
• 10% chance of becoming a severe case

Why Monte Carlo Simulation?
• Early likelihood of meeting project
milestones and deadlines

• Predicts schedule and cost overruns
• Quantifies risks to assess risks bette...

