Discussion and Response: what role end-users typically play in incident reporting?

profilespluousp
635discussion5_post1.docx

by Irina Dave 

The goal of an effective information security incident management strategy is to process incidents as effectively as possible and minimize the impact of the incident on the institution (educause, 2021). End-users play an important role in incident- reporting. End users are the main participants in noticing any incident. When an application or website is launched it is not 100% quality assured. So, when the user starts using the application/ website, there are chances that they may find issues and incidents. Finance applications, e-commerce applications are those which required user’s personal and financial information. In such applications, the owner organization has taken care of all security and privacy aspects but there are multiple negative factors that are interested in breaching the privacy. In that case, end users are the only source who can help to resolve the issue. End- users should be encouraged to report suspicious incidents. Because of their help, the incident can be resolved in less time. Today, users get lots of SPAM calls about some offers, bank deals, information about their bank account. In this scenario, spam callers ask for the user’s personal information like their name, birthdate, email address, bank account number and at the end, they ask for the user’s pin. The spam caller is so manipulative that they manage to take the user’s number and steal money from their account. In this scenario, when the user reported this issue, all the banks got alerted. They started sending texts, emails and calls to their users stating that no bank will ask for your pin so never share your pin. So, with this action event users got to know what to share and what not to share on the phone call. This is only one example but there are many others which states that users are equally important for solving the incident. Incident reporting mechanisms, such as phone numbers, e-mail addresses, online forms, and secure instant messaging systems with which users can report suspected incidents; at least one mechanism should permit people to report incidents anonymously (Whitman, Mattord & Green, 2014).

References:

Incident management and response. EDUCAUSE.edu. (n.d.). https://www.educause.edu/focus-areas-and-initiatives/policy-and-security/cybersecurity-program/resources/information-security-guide/incident-management-and-response.

Whitman, M. E., Mattord, H. J., & Green, A. (2014). Principles of incident response and disaster recovery. Course Technology Cengage Learning.