Disaster Recovery and Business Continuity Plan
1
3
Financial Service Security Engagement
Learning Team C
CMGT/400
April 8th, 2019
Ellen Gaston
Financial Service Security Engagement
· Create a plan that addresses the secure use of mobile devices by internal employees and external employees as they use mobile devices to access these applications.
· Recommend physical security and environmental controls to protect the data center which runs the on-site applications.
Introduction
Integrating cloud-based, customer relationship management (CRM) software application with the on-site software applications that manage customer accounts and investment portfolios can assist a firm to create more leads, increase revenue, minimize the cost of sales, and improve customer services. However, this system has some security risks and requires an organization to create a plan that addresses its secure use.
Mobile Gadget Security/Bring Your Own Device Plan (BYOD)
This involves creating a gadget usage policy, before issuing them to workers. This entails limitation of its use and probable actions against its violation (Michener, 2015). Employees also are taught on how to mitigate security risks of mobile phones. If workers can utilize their personal gadgets, BYOD security policy is created, which comprises of installing distant wiping application on all devices to store data accessed from the organization (Michener, 2015). Organization should install current antivirus software to all devices to prevent hacking and loss of data. The content stored in the mobile devices should be backed up on organization’s computers on regularly basis to make sure that the data is safe if a gadget is stolen or lost.
Selecting Passwords
Passwords meant for the devices should be strong enough and not common to any third party. This ensures privacy as it prevents data linkage to unwanted individuals. On a different point, carrying out consistent mobile security audits and penetration assessment is one of the physical securities and environmental control measures. In this case, a firm hires a recognized security testing company to audit their gadget security and carry out penetration assessment (Michener, 2015). This ensures data protection as any noticed channels of data linkage drives the firm to upgrade its system.
· Propose audit assessment and processes that will be used to ensure that the cloud-based CRM software provider uses appropriate physical security and environmental controls to protect their data centers which run your cloud-based CRM software.
· Develop identity and access management policies for both the on-site systems and the cloud-based CRM.
Customers should be aware that unique data security issues arise in a cloud computing environment. For example, in an ASP environment, a single physical server may be dedicated to the customer for hosting the application and storing the customer’s data. However, in a cloud computing environment, technologies and approaches used to facilitate scalability, such as virtualization and multi-tenancy, may result in customer data being stored on a physical server that also stores data of the provider’s other customers, which may increase the risk of unauthorized disclosure. We are recognizing the unique security and privacy risks related to a cloud computing service delivery model and calling on the government for legislation to enhance and strengthen security and privacy protections. (Foley & Lardner, 2013)
To address data security issues, customers should conduct due diligence regarding the security practices of a provider and include specific contractual protections relating to information security. Part of a customer’s due diligence should include identifying the location of the data center where the data will be physically stored and who may have access to the data. If the data center is in a foreign country, then the customer should be concerned as it may not have an opportunity to inspect the foreign location to ensure it complies with customer’s information security requirements. Even if the data center is in the United States, help desk personnel accessing the data could be in a foreign country with limited or different security and privacy laws. (Foley & Lardner, 2013)
In addition, the location of the data and the ability of data to be widely distributed across different jurisdictions present complex issues of which law is applicable in a given transaction. Currently, there is very little guidance from courts on these conflict of law issues. For example, if personally identifiable information is in Europe, then European law may govern that information regardless of what is provided for in the contract. Also, a Vendor may have multiple data centers, each located in a different state in the United States, with each state having its own law regarding data privacy and security. Therefore, to minimize potential issues, the customer should consider adding a restriction against offshore work and data flow to foreign countries, including a requirement that the data center (including the hosted software, infrastructure, and data) be located and the services be performed in the United States, and that no data be made available to those located outside the United States. (Foley & Lardner, 2013)
In addition, the customer should identify who will be operating the data center. If the provider is not operating the data center itself (e.g., the provider is the owner of the software and will be providing support, but is using a third-party data center to host the software), then the provider should be required to ensure that the third-party host complies with the terms of the agreement (including the data security requirements), accept responsibility for all acts of the third-party host, and be jointly and severally liable with the third-party host for any breach by the third-party host of the agreement. Also, the customer should consider entering into a separate confidentiality and nondisclosure agreement with the third-party host for the protection of the customer’s data. If the provider ever desires to change the host, the provider should be required to provide the customer with advance notice, and the customer should be given time to conduct due diligence about the security of the proposed host and the right to reject any proposed host. (Foley & Lardner, 2013)
· Recommend cryptography and public key infrastructure (PKI) uses which could be used to increase security for these systems.
Due to the sensitive nature of the accounts that we handle, and the need to uphold a reputation of trust encryption should be implemented. The use of public key infrastructure and the use of digital certificates that are company generated, outsourced, or public fills this space. The use of digital certificates is key to this infrastructure. The certificates can be issued to a user, computer, device, server, or webpage. This certificate must come from a place that is trusted. These certificates contain who issued the certificate, who the certificate is issued to, expiration dates, public key, digital signature. The digital signature involves hash value. The hash value is used in concert with public and private keys for encryption methods. A public key infrastructure being that this is infrastructure and if it is put into place it will give the business opportunities for use because it is there. The opportunities include SSL, digital signatures, Encryption, smart card login, software code signing, secure e-mail, encrypted file system, VPN, 802.1x port-based authentication. These benefit the company by giving an extra layer of security to employees. This also benefits customers in any applications or web-based services with the use of AES encryption from a man in the middle attack. The reputation of the company is an asset that gets overlooked until it is too late by using methods that will ensure the security of our employees and our customers, we make a stance that we are our services and our clients seriously. This will hopefully generate more revenue in the future as our clientele grows along with our business scalability by putting down a good security infrastructure.
References
Adams, C., & Lloyd, S. (2007). Understanding PKI: Concepts, standards, and deployment considerations. Boston: Addison-Wesley. Retrieved from https://books.google.com/books?hl=en&lr=&id=ERSfUmmthMYC&oi=fnd&pg=PP23&dq=pki&ots=nsynQXqjLp&sig=8aYQMuZvUxvfMVeSX5tULHD5jhI#v=onepage&q=pki&f=false.
Michener, W. K. (2015). Ten simple rules for creating a good data management plan. PLoS computational biology, 11(10), e1004525.
Gartner Highlights Five Attributes of Cloud Computing, Gartner, Inc. (June 23, 2009), at http://www.gartner.com/it/page.jsp?id=1035013.