The Essay (about 2 pages in APA style):
For your chosen business (the business of your client) your prior choices now drive your information security requirements. Most businesses already have some privacy and confidentiality requirements, however, is this new data analytics function introducing additional considerations? (Sarbox? HIPAA?)
State the impact on the business in terms of information security that will be caused by the introduction of this new data analytics function. Is your data in the cloud?
Compare the new level of InfoSec requirement against the (assumed) initial security precautions already in place at this business. Describe the upgrades required to the security configuration.
Note there are security considerations for data “at rest” and for data “in motion”.
Assume the client already has some minimal form of disaster preparedness (DR) scheme whereby on-site servers (if any) are backed-up to other storage devices and those backups can be retrieved if needed by an offsite DR plan. Is this enough to accommodate your new data analytics design?
How vital is the end product of your data analytics function to be to the continued operation of the business? If it produces reports on future trends for instance, then perhaps the new InfoSec requirements are fairly low. If you have recommended a scheme that will become vital to the business’s continued operation, then probably the InfoSec and DR precautions increase. There is a measure of appropriateness here for these security precautions.
There are significant cost considerations too. If you recommend a whole secondary data center just to support DR, that recommendation must be absolutely essential, or else the costs involved will damage your entire recommendation. Here too is a measure of appropriateness.
Similarly, other security-related precautions such as guards at the front door, gated parking lots, etc are huge cost items. Do not add these casually.
Your essay must state the (assumed) initial security situation and DR situation (if any) of the client (the “before”) and then state the expected upgrades / enhancements required (if any) to support the data analytics function (the “after”).