Objectives Develop questions to gain further insight and help get the client and tester on the same page Create a sample scope for an security assessment Create and revise Rules of Engagement for the test

Information Technology Project Management
9th Edition
ISBN:9781337101356
Author:Kathy Schwalbe
Publisher:Kathy Schwalbe
Chapter11: Project Risk Management
Section: Chapter Questions
Problem 3RC
icon
Related questions
Question

Objectives

  • Develop questions to gain further insight and help get the client and tester on the same page
  • Create a sample scope for an security assessment
  • Create and revise Rules of Engagement for the test

Overview

You were given a Request For Proposal  (RFP) but it seems to be lacking enough details to determine what the client is requesting for a test. We will need to come up with some information and questions to discuss with the client to determine what exactly they are wanting. This will allow both the client and the tester to be on the same page prior to beginning any assessment. We will be building a Scope and Rules of Engagement (ROE) to determine what is in scope and the document that outlines specifics of the project and how it will occur.

Below are some of the key points pulled from the RFP that was lacking a lot of details:

  • The test is for CIT-E Corp with 2,000 employees located throughout the United States
  • They want a penetration test from either an outside company or group within the company
  • Minimize or eliminate business risks and exposures 
  • Overall goal is to ensure the appropriate security controls are implemented and functioning to preserve the confidentiality, integrity, and availability of the data they house and are responsible for.

Objectives

  • Develop questions to gain further insight and help get the client and tester on the same page
  • Create a sample scope for an security assessment
  • Create and revise Rules of Engagement for the test

Overview

You were given a Request For Proposal  (RFP) but it seems to be lacking enough details to determine what the client is requesting for a test. We will need to come up with some information and questions to discuss with the client to determine what exactly they are wanting. This will allow both the client and the tester to be on the same page prior to beginning any assessment. We will be building a Scope and Rules of Engagement (ROE) to determine what is in scope and the document that outlines specifics of the project and how it will occur.

Below are some of the key points pulled from the RFP that was lacking a lot of details:

  • The test is for CIT-E Corp with 2,000 employees located throughout the United States
  • They want a penetration test from either an outside company or group within the company
  • Minimize or eliminate business risks and exposures 
  • Overall goal is to ensure the appropriate security controls are implemented and functioning to preserve the confidentiality, integrity, and availability of the data they house and are responsible for.                            provide full source link with. Need help with this please.
Expert Solution
steps

Step by step

Solved in 5 steps

Blurred answer
Knowledge Booster
Maintenance
Learn more about
Need a deep-dive on the concept behind this application? Look no further. Learn more about this topic, computer-science and related others by exploring similar questions and additional content below.
Similar questions
  • SEE MORE QUESTIONS
Recommended textbooks for you
Information Technology Project Management
Information Technology Project Management
Computer Science
ISBN:
9781337101356
Author:
Kathy Schwalbe
Publisher:
Cengage Learning
MIS
MIS
Computer Science
ISBN:
9781337681919
Author:
BIDGOLI
Publisher:
Cengage
Principles of Information Systems (MindTap Course…
Principles of Information Systems (MindTap Course…
Computer Science
ISBN:
9781285867168
Author:
Ralph Stair, George Reynolds
Publisher:
Cengage Learning
Management Of Information Security
Management Of Information Security
Computer Science
ISBN:
9781337405713
Author:
WHITMAN, Michael.
Publisher:
Cengage Learning,