ITC561 CSU | Assessment item 4 Risk, Security and Management | IT

Home Recent Questions ITC561 CSU | Assessment item 4 Risk, Security and Management | IT



VideoDev Ltd is a video and production development company which works for clients across Australia and New Zealand. The company is considering moving some of its computer infrastructure into the Cloud. The VideoDev Board is contemplating this move as a way to increase the company’s flexibility and responsiveness, as well as to achieve some savings on the cost of maintaining their ICT infrastructure.

VideoDev has engaged you as a consultant to advise them on the use of Cloud Computing in their daily operations. They have some 100 video production, engineering and support staff that work on different projects for clients in Australia and New Zealand.

You were recently engaged to advise on re-factoring their video processing application to use a microservices approach. The VideoDev Board is keen to start to move to this direction as it sees the possibilities that it will open up for VideoDev in the future. They have also decided to start planning to migrate their existing web services from their two on-premise data centres to a public cloud.

The company is considering the following strategic proposal:

• They plan to retain the Sydney data centre for data storage. This would entail updating their Active Directory and data storage infrastructure, and moving all other infrastructure into the Cloud.
• They plan to move all their Web Services into the Cloud in order to provide an increased responsiveness to customer demand as well as an enhanced level of HA (High Availability) in supplying data to their customers and staff.
• They are considering changing their current web softw are architecture to take advantage of the flexibility and scalability that can be gained by moving to a Microservices model (this would entail the use of such services as AWS Lambda or Azure Functions, Containers, Data Services, and Cloud Edge capability and monitoring).

The VideoDev Board is contemplating this strategy as a way to increase the company’s flexibility and responsiveness. The Board also expects to achieve significant savings on the cost of maintaining their ICT infrastructure by closing one of their existing data centres. They appreciate that this would entail retraining for their existing ICT staff so tha they can manage the new Cloud based infrastructure.

You have also advised the VideoDev Board that their Threat and Risk Assessment (TRA) needs to be updated as a result of these architectural changes. The Board has asked you to update the TRA as a matter of urgency.

The Board is also concerned about how this strategy will affect their BCP (Business Continuity Plan) and their backup and disaster recovery strategies.


Your team has been engaged to provide a report for the VideoDev Board on their proposed strategy.

Team Setup

This assignment is a team assignment. The rationale for using a team approach is that most IT risk management assessments are normally done by teams of between 2-5 Architects, Information Security experts, Operations and Business leaders for each problem. You will be assigned to a team and the team, as a whole, will be responsible for the development of the risk assessment.

Team Member Responsibilities

Each team member will be assessed on:

• The final risk assessment presented by the team;
• The individual contributions that they have made to the risk assessment. This will be shown by the entries that they have made in the Team forum;
• Team members should note that:

A total of 20% of the total marks for this assignment are for individual contributions to the team task;

A team member without any individual contributions in the Team Forum will be regarded as having not contributed to the risk assessment. This will result in either reduced marks or no marks being awarded to that team member for this assignment.

The tasks:

The team’s task is to prepare a report for VideoDev that discusses the following:

1. Describe which Cloud architectures you would employ to assist VideoDev to meet the Board’s strategy of moving their web services to a MicroService approach?
a. Describe each of the architectures that you would use, along with your reasons for deploying it. (5 marks)
b. Describe the benefits and issues that would be the result of your deployment of these architectures. (5 marks)

2. Describe the risks that you see associated with this new MicroServices strategy. You should name and describe each risk that you identify, and then describe a possible control for the risk. This should be presented in a tabular form. (20 marks)
3. Describe the general Information Security steps and controls that you would recommend to the Board to secure these MicroServices. You will need to explain to the Board your reasons for recommending these particular security steps. (10 marks)
4. Discuss briefly what you would recommend should be included in VideoDev’s BCP as a result of their adoption of a Microservices approach. You will need to consider, as a minimum, the issues of application resilience, backup and disaster recovery. This section should be no more than 2 pages. (10 marks)
5. Discuss the requirements that VideoDev will need to consider in order to conduct remote administration, resource management and SLA management for its proposed

MicroService approach. This section should be no more than two to three pages in length. (10 marks)

6. The VideoDev board wants to know what you recommend as the best migration strategy and process for the migration of their web services to a MicroService approach.

a.    Describe the steps that you would include in the plan to migrate these services. (10 marks)
b.    What are the critical points and issues that you see occurring at each of these steps? Explain why you see these points or issues as critical. (10 marks)

Similar Posts

Order Now

Latest Reviews


Payments And Security