I need this assignment wrote orignally as if I were the CIO/CISO, not copied and paste You are the CIO/CISO of St. Elgius. The organization has no strategy around vulnerability management or patch management. There are both externally and internally facing vulnerabilities present. Additionally, endpoint vulnerability is very bad as there is no patching remediation program in place. Server vulnerabilities are better as the hospital uses some servers that are cloud hosted in AWS which are patched automatically. How would you implement a vulnerability management program? What tooling would you choose? Would your approach change for external vs. internal vulnerabilities?

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question

I need this assignment wrote orignally as if I were the CIO/CISO, not copied and paste

You are the CIO/CISO of St. Elgius. The organization has no strategy around vulnerability management or patch management. There are both externally and internally facing vulnerabilities present. Additionally, endpoint vulnerability is very bad as there is no patching remediation program in place. Server vulnerabilities are better as the hospital uses some servers that are cloud hosted in AWS which are patched automatically.

  1. How would you implement a vulnerability management program? What tooling would you choose? Would your approach change for external vs. internal vulnerabilities?
  2. How would you put a corresponding patch management program in place to mitigate identified vulnerabilities?
  3. For both #1 and #2, discuss how your approach would change for servers vs. endpoints given the facts above.
Expert Solution
Step 1

Note: As per our company guidelines, we are supposed to answer only one question. Kindly repost other questions as separate questions.

 

As a CIO of St. Elgius, Vulnerability management is a method that may be used by companies to monitor, minimise, and remove vulnerabilities in existing system/server. It entails detecting and categorising vulnerabilities such that suitable safeguards or remediations may be implemented.

 

steps

Step by step

Solved in 4 steps

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY