Milestone 4

profileRak1993
Milestone3_RakeshKalumula.pdf

Running head: MITIGATION OF SECURITY INCIDENT 1

Mitigation of Security Incident

Name: Rakesh Kalumula

Student Id: 002836752

MITIGATION OF SECURITY INCIDENT 2

Mitigation of Security Incident

The information technology has taken the world by storm, with a precedent pace in the

applications being conducted. Numerous benefits have come with the use of these technologies

with companies resorting to using these technologies to achieve their milestones. However, some

disadvantages have come with these advances; data breach cases have been rampant with the

Capital One case being the most vivid in this regard. The digital fraud that led to external access

of more than a hundred million clients` data being at risk meant that the impact was devastating.

Therefore, this paper calls for some of the most effective ways in which the incident would be

mitigated and the damage prevented from taking place.

First, the Capital One incident would have been prevented by the use of the zero-trust

technology coupled with a software-defined technology that only allows authorized individuals.

This is the first measure that should be considered in organizations of this caliber due to the

advances that have taken place in the world (Torkura et al. 2019, September). The organization

has employed people from different walks and it’s only through the use of strict control and

monitoring digital devices that the management will be able to identify any malicious activities

and prevent further damage from taking place. This would also mean that employees can only

access areas that they are allowed hence limiting chances of unknowingly breaching the facility`s

data.

Secondly, the company should assess the damage, identify the clients whose data was

breached, and initiate appropriate measures. In this regard, it would be important that the

company`s clients are trained in the best ways of having strong passwords. The passwords should

MITIGATION OF SECURITY INCIDENT 3

be strong enough to prevent any entry whenever from an intruder. This would also entail training

the clients on why they have to keep their passwords secret and not to share with anybody so that

they can avoid similar incidents that would put their data at risk (Chowdhury, Lau &

Pittayachawan, 2019).

Thirdly, there is no leaving anything for chances. The Capital One will be mitigated by

having in place a credit monitoring for all the affected clients. It’s not clear if the data was used in

the breach but the management should not ignore anything at this level. As a result, both the

management and the clients will have to work hand in hand to ensure that there is no future data

breach. The use of sites like credit karma should be able to make an individual to easily identify

and notify the client of any activity taking place. Therefore, through the use of these alerts the

client and the management should be able to remain updated on any of the activities taking place

and initiate appropriate measures whenever required.

Besides that, the company also advocates for the freezing of the credit accounts to help in

the mitigation of the security incident. This will give the fraudsters a hard time accessing the

account but it’s not a guarantee that the account is secured. This is because access to one`s driving

license any official document one is likely to be allowed to access the account without the owner`s

consent. Therefore, this is not the most appropriate measure that can be applied at this level but it

helps in delaying the attack from taking place.

Finally, the overall mitigation measure for such incidents is being alerted on all fronts.

Both the clients and the management team have to be alert; this is an issue that requires collective

responsibility. As technology advances the management of these vices becomes complex.

Therefore, to effectively manage and prevent such incidents from taking place it’s critical that they

MITIGATION OF SECURITY INCIDENT 4

all remain alert and always upgrade their software system with the changes taking place in the

sector (Torkura et al. 2019, September).

In summary, Capital One breach is an incident that would have been prevented if

appropriate security measures were considered. However, due to mistakes committed initially,

there must be the use of appropriate mitigation measures to prevent such incidents in the future.

MITIGATION OF SECURITY INCIDENT 5

References

Chowdhury, P., Lau, K. H., & Pittayachawan, S. (2019). Operational supply risk mitigation of

SME and its impact on operational performance. International Journal of Operations &

Production Management.

Torkura, K. A., Sukmana, M. I., Cheng, F., & Meinel, C. (2019, September). SlingShot-Automated

Threat Detection and Incident Response in Multi Cloud Storage Systems. In 2019 IEEE

18th International Symposium on Network Computing and Applications (NCA) (pp. 1-5).

IEEE.