I work for Department of Commerce (BEA), Bureau of Economic Analysis here in the Washington DC area. I am very much interested to write a Risk Analysis Report for Bureau of Economic (BEA). There are two main reasons that interest me in conducting the research;
Risk Assessment Report Project Proposal
I work for Department of Commerce (BEA), Bureau of Economic Analysis here in the Washington DC area. I am very much interested to write a Risk Analysis Report for Bureau of Economic (BEA). There are two main reasons that interest me in conducting the research;
- We here at the Bureau deals with the collection of sensitive accounting data from multinational companies (U.S. Reporters) that have subsidiaries in the rest of the world. The data is collectedannually/quarterly through survey forms electronically as well as manually. The U.S. reporter is required to submit the accounting data for the head quarter as well as the subsidiaries in the rest of the world as it is the Federal Mandatory requirement, http://www.bea.gov/international/federalregs.htm
- I am interested in transition from an Accountantto a Systems Accountantposition in the near future and for the same reason I am completing my MS in “Accounting and Information Systems”.
Purpose: The purpose of this risk assessment is to evaluate the competence of BEA’s security system to stand against the external/internal threats. This risk assessment provides a structured qualitative assessment of the operational environment. This assessment would address sensitivity, threats, vulnerabilities, risk as well as safeguards. The mission here is to find cost-effective approach protections to lessen threats and related utilizable weaknesses.The Bureau computing requirements have been supported by a single local area network (LAN) and all of the Bureau’s IT infrastructure components are managed by BEA’s Chief Information Officer.
Within BEA’s centralized IT environment,the departmentcontinues to evaluate alternative means of providing critical services more efficiently in order to avoid unsupportable future cost increases. BEA continually evaluates opportunities to implement cloud computing within the framework of the Bureau’s requirements for maintaining (1) the integrity and timeliness of our critical data on economic activity, and (2) the confidentiality of our company level source data.
Scope:The nature of BEA’s data is such that unauthorized exposure or access of the data could cause threat to the existence one company against the competitor. The scope of the risk assessment helps to use resources and controls, both implemented or planned to eliminate or manage vulnerabilities exploitable internal/external to the Bureau. The Vulnerabilities to the Bureau system these threats could result in;
- Unauthorized disclosure of data
- Unauthorized modification to the system as well as data
- Denial of service, access to data, or both to authorized users
From the Bureau’s point of view due to the sensitive nature of the data it needs to be protected to keep the confidentiality, integrity and availability of the data.
Website to be used to collect the data for risk Analysis: