Orion Inc DMZ Project Assessment

1  Scope Statement

1.1  Vision Statement

(How the project contributes to the overall vision of the company)

DMZ Standardization minimizes network disruption threats through our Internet connections so we can carry our company’s vision of creating value by transforming the practice of medicine through biotechnology.

1.2  Business Need

(Project justification - Problem to be solved or opportunity to be explored.)

Threats to network and data security via the Internet has continued to escalate. With each of our Global IT Operation having Internet connectivity as well as the Information Management group in the USA, there is a need to standardize network security policies, procedures and network architecture enterprise-wide to contain these threats and thereby allow business operations to function. The DMZ Standardization project is one component of an enterprise-wide network standardization program.

1.3  Project Description

(Characteristics of the product or service that the project was undertaken to create.)

Assess the feasibility of defining and deploying an enterprise wide DMZ network standard.

1.4  Project Deliverables (Scope)

(List of summary-level sub-products whose full and satisfactory delivery marks project completion.)

Is / Is Not
DMZ network standards document that incorporates industry best practices for architecture, design, procedures and policies. / Enterprise-wide information security risk assessment
Timeline, scope and cost of standardizing DMZ network for all IT Ops and IM. / Physical security standards.
Recommended approach and phases to standardized DMZ deployment based on budgeted amount. / Identity security standards.
Project review meeting scheduling and presentation for approval/disapproval.

1.5  Project Objectives

(Quantifiable criteria to be met to consider the project a success. Time, cost, performance and other objectives – business and technical. Best practice is to also include milestones leading up to project completion.)

Objective / Criteria for Evaluation
Create a DMZ standards document. / Standards document created by the first week of November and available for management review.
Estimated project cost, duration, and scope for the enterprise-wide deployment of the DMZ standard / Estimate of Implementation phase baseline completed by the first week of November and available for management review.
Present the project to the Project Review meeting on the second week of November. / Project reviewed by management via the project review meeting on the second week of November.
Assessment phase completed on time, within budget and with all identified deliverables completed. / Assessment phase completed by second week of November, within budget and with all identified deliverables completed.

1.6  Assumptions

1.6.1  Resources are available to complete deliverables on time.

1.6.2  Scope is limited to DMZ network standardization only.

1.7  Constraints

Assessment phase must be completed by the second week of November.

1.8  High-Level Risks

Risk Description / Trigger / Impact - Cost, Scope, Budget (C,S,B)

1.9  Approval Signatures