¶ … Malware Incident Response Plan
The Policy
This plan is devised to mitigate the effects of malware used during a cyber-attack on a company's security system. The plan uses three levels of staging -- set up, response and recovery. This plan is based on evidence from research that has been conducted to protect the highest levels of secure documents.
Set Up
The first priority of the plan is to educate all levels of the company regarding the danger incurred from breaching security protocols on their work stations. Whereas it may only seem necessary to conduct in-depth training with individuals new to the company, it has been shown that executives are the most lax when it comes to cyber security. Therefore, a training schedule which updates users regarding any new information and reminds them regarding what they need to be doing every day to protect the overall system is essential. This training will recur in a semiannual basis to make sure that it is fresh in the heads of the individuals concerned.
The training that every employee receives will not be at the same level as that received by the information technology personnel tasked with detection and response. These individuals need to be trained daily on the threats that could occur to the particular systems the company uses. This means that there will be a dedicated threat assessment team (consisting of at least two people) who are responsible for monitoring outbreaks that have occurred in other networks. These will be assessed to see if they could possibly endanger the operations of this company. The importance of this cannot be overstated. There are constant threats occurring against all manner of server systems, and it is necessary to determine if that type of threat, no matter how small a risk, could occur within this company's system. This team will report to the rest of the IT department on a daily basis to make sure that all are aware of the current threats plaguing the industry. Also, a "Threat Sheet" will be generated and distributed to these personnel daily to make sure that they have a constant reminder of the current issues. All company personnel will receive a daily email describing what threats they need to be aware of also.
The priority of training is something that should occur to any organization, but it is also necessary to devise layers of security that start with the people using the different stations. A person's position within the company dictates the level of information to which that individual should be privy. A line employee, depending on the type of employment, will have access only to that information that is crucial to their job description. It is unnecessary to give that individual access to information which does not have to do with their job unless that are promoted to another position or given a project for which it is required. All supervisory personnel will have a higher level of access because they have responsibility, at least in part, for a group of individuals and their employment. Thus, this person will have another level of access to the system. This procedure follows throughout the entire organization until it reaches the highest level of the company. Most likely information systems technicians and staff will also have the highest level of security clearance within the company because they may be required to service and station within the company. The policy may have a caveat that when an IT professional is working on a system, he or she must have that access checked by a supervisor or another officer. This plan requires that any IT access above the supervisory level have this protocol in place.
One of the duties of the IT office will be to protect all company computers with the latest security software. Threats happen constantly across the globe (though not necessarily to an individual company), so there also has be attention paid to updates for the software and an awareness by the IT office that some software designs are not updated often enough or may longer work with the hardware of this company. Therefore, there will be updates as often as they are available (sometimes this will happen daily, but the software should be routinely checked at least once per week), and technicians will constantly seek to upgrade the software as more appropriate programs become available. Since there are multiple detection systems available, this plan requires antivirus protection...
Metrics, Implementation, and Enforcement (Security Governance) How can you determine whether there has been a malware outbreak? The threat situation today has become more dangerous than in the past. Security and safety threats have been increasing in an alarming rate; there are more than 70,000 brand new bits of malware recognized daily. Well-funded cybercriminals have been currently making advanced malware that has been made to bypass present security options by launching prior
Terrorism in Relation to International Governance The 9/11 terrorist attacks on the United States highlighted the global threat of terrorism since it changed the ways in which the world views terrorism. Actually, the attacks demonstrated the evolution of the threat of terrorism that has become a major security threat across the globe. Given the global dimension of terrorism, state actors and the international community has become increasingly concerned and developed various
Most well-known was Robert Scoble of Microsoft. With the 2004 U.S. Presidential elections, blogs' growth accelerated dramatically as nearly every news network, candidate in both U.S. Senate and House of Representative races, and political pundit has their own blog competing for the publics' attention. The era of 2004 to today in fact has created a blogging industry that is pervasive in its availability of publishing platforms (USC Annenberg School of
IT Fraud Evaluate the factors that add to corporate fraud The business fraud can be credited to conditions emerging from deceptive monetary reporting and misappropriation of possessions. These conditions are 3 and all 3 features of the fraud triangle have to exist for fraud to take place. Management or staff members have to have the reward or pressure to dedicate fraud, see the opportunity emerge and have the ability to justify the
company code of ethics for Boeing. In this document I will explore Boeing's code and attempt to reveal important items relevant to understanding how a functional code of ethics may be applied to a large organization. I will first describe a general background of the company to help provide context in this evaluation. Next, I will give an overview of the code of conduct and highlight important details that
Global Refugee Regime Seems to Be Veering Away From Traditional Rules As the threat of war looms large, the situation of those displaced because of violence and fights is becoming the focal point of talks amidst humanitarian groups. Many wrote about the situation in Afghanistan. The last many years have brought about quite a lot of enormous "refugee movements and humanitarian emergencies." More than 50 million people have been displaced by
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now