1 / 14100%
Running Head: ISE 510 1
SNHU
ISE 510 Security Risk Analysis & Plan
Security Breach Analysis and Recommendations
FINAL PROJECT
Delapaz Carlos
Due October 13, 2019 2359 EST
=====================================
KEEP THIS ON TITLE PAGE
1. No Direct quotes allowed – (reword or paraphrase; and add in-text citation)
2. Include page numbers for my ability to check the source of your work efficiently.
3. All papers are extensively checked for originality, academic integrity, and authenticity.
KEEP THIS ON TITLE PAGE
ISE 510 2
I. Introduction
Limetree Inc. is a well-known research and development business entity that specializes
in research projects in various areas such as biotechnology, healthcare, and other cutting-edge
industries. It works with private corporations as well as the federal government. Lately, the
business undertaking has been experiencing substantial growth in the operational industry but it
is concerned about the rising security breach incidents that are taking place in the unpredictable
industrial setting. One of the core objectives of the business undertaking is to strengthen its
information security program so that it can achieve its business goal.
The Limetree Inc. organization has been facing significant security breaches lately. It
believes that confidential information was stolen from it including Personal Health Information
(PHI) that were utilized in a research study. The existing security protocols and policies are
inadequate as they do not adhere to the existing industry standards. The security breach incident
could adversely impact the survival and sustainability of Limetree Inc. in the operational
industry. Malicious cybersecurity incidents had cost the United States economy between USD 57
billion and USD 109 billion in the year 2016 alone. Both large and small businesses need to
identify their security vulnerabilities and strengthen their cybersecurity framework so that
security breach incidents can be prevented or avoided.
The paper captures the security breach incident that took place in Limetree Inc and
compromised the quality of security of the firm. The key vulnerabilities of the entity have been
identified and a robust incident response plan has been designed so that similar kinds of security
incidents could be prevented in the future. A security test plan has been designed and suitable
recommendations have been designed to strengthen the security infrastructure of the
organization.
II. Security Breach
Some of the likely causes of the breach include the poor security posture of the organization,
the lack of proper documentation of the security policies and the lack of proper training of
employees on security awareness. At present Limetree does not have a robust security
framework in place which could give cyber attackers an upper hand to exploit the vulnerabilities
of the organization. The low security posture of the firm is a major IT concern that could have
led to the security breach incident.
A. Attack Location:
The attack that took place in Limetree impacted all the employees of the research
organization especially the research team. This is because personal health information (PHI) that
was used in a recent research study was stolen by the attackers. The physical and IT environment
of Limetree has a number of gaps that could have given access to online hackers to invade the
system and compromise the security.
B. Attack Method and Tools:
2
ISE 510 3
In order to carry out the security breach attack, the insider data theft attack is a probable
method that could be used by an attacker. In such an attack, sensitive information relating to the
company could be stolen without the knowledge of the employees. As the employees lack proper
training on security awareness, this method must have been used to conduct the security breach
in Limetree.
C. Vulnerabilities:
As per Jack Sterling, the Security Manager of Limetree Inc, even though the firm has faced
security incidents before, no previous documented history of incidents was stored which could be
used to identify the corrective measures that were taken to deal with the incidents. Similarly, the
process of sharing information on a computer incident is quite lengthy. For instance, the
administrators escalate the incident to the IT manager, who reports incidents to the security
manager if they are considered to be relevant. These were the two major vulnerabilities that were
exploited to affect the attack as per John.
The physical vulnerabilities that Jack Sterling has identified include:
Users are not given training on security awareness
Visitors just sign in at the front desk and are allowed to walk in to see employees at their
respective offices.
The users are generally allowed to bring in their own laptops and connect to the corporate
system.
The vulnerabilities that Jack Sterling has identified in the Administrative Office workstations
include:
The low level of security setting of the Internet Explorer browser and the absence of a
standard browser for the environment.
The low disk space for the SQL database log which is overwritten with new information
when it is full.
No segmentation or authentication between the wireless and wired LAN. Visitors are
given access code to use the wireless network of the company.
Absence of logging of network activities on any of the switches.
The public-facing web server is a part of the LAN and it acts as the key point where
internet users get information on the company.
Absence of documented security policy, or computer use policy.
Lack of a properly documented process for changes to the system.
Absence of any contingency plan.
The vulnerabilities that Jack Sterling identified regarding the Wi-Fi was that the Wireless
network was available with clearly advertised SSID, and it was a part of the local area network
(LAN). There was no segmentation or authentication between the wireless and wired LAN which
was a major security blunder. Visitors are given access code to the wireless network at the front
desk which increases the vulnerability of the firm’s network.
III. Incident Response
3
ISE 510 4
The purpose of the incident response plan is to help the research and development
organization to be prepared in case any security incidents arise. It would strengthen the security
infrastructure of the organization and minimize its vulnerability on the cyber platform.
The current Incident Response Plan at Limetree is very ineffective and weak. I case any
security incidents arise, the system administrators are notified of the same and they escalate the
issue to the IT Manager. He is then responsible to report the incident to the Security Manager if
it is considered to be an actual incident. Currently, there exists no documentation process so
there is no record of previous security incidents.
A. Purpose of the Incident Response Plan
The purpose of the incident response plan is to help the research and development
organization to be prepared in case any security incidents arise. It would strengthen the security
infrastructure of the organization and minimize its vulnerability on the cyber platform.
B. Incident Response
A new Incident Response Plan has been proposed that could be introduced at Limetree to
upgrade its security posture. The process has been designed so that the Incident Response Team
could take necessary measures to deal with the security issue and make sure that the extent of the
damage can be curbed to the best possible extent. The main phases that would be involved in the
plan have been highlighted below.
1) Preparation - In the preparation stage, Limetree must make sure to develop suitable
capabilities so that security incidents could be prevented in the future. So the research and
development organization must ensure highly-functional and effective networks, systems,
hardware, and applications are employed.
2) Identification - Limetree has to confirm, categorize, determine the scope and prioritize
various kinds of risks that could arise in the IT ecosystem. Such an approach would enable the
business to get a better insight into the threats and risks that could affect the business in the cyber
setting.
3) Containment - Necessary steps have to be in place so that the damage can be minimized or
mitigated to a possible extent. Limetree has to ensure the affected devices are disconnected from
the internet so that the spreading of the breach could be restricted (Supplement to ISE510
Security Risk and Planning, 2019).
4) Eradication - In order to eliminate the cybersecurity threat, Limetree has to ensure that the
root cause of the issue is dealt with. So, all malicious elements have to be securely removed and
the system would have to be hardened and patched.
5) Recovery - Limetree has to assess the incident to get a detailed insight into the procedural and
policy implementations (CRR Supplemental Resource Guide, 2019). At this stage, the business
undertaking would have to restore the affected systems so that they could be restored and
brought back into the business environment. The firm must ensure to document each and every
process so that in the new future it could prepare itself in case a similar security breach incident
arises (Blair, 2015).
6) Lessons Learned – After the in-depth investigation relating to the cybersecurity incident has
been completed, a post-action meeting must be conducted by the Incident Response team at
Limetree. All the members would get the opportunity to discuss the learning from the data
4
ISE 510 5
breach incident. This meeting would allow them to assess and document every little aspect
relating to the security incident. Some of the main questions that need to be addressed relate to
the following areas:
The changes that need to be introduced in the security model of Limetree so that its
security posture can be strengthened.
The training process that must be implemented for the employees of the firm so that
their security awareness can be improved
The exact weaknesses and vulnerabilities that were exploited by the cyber attackers
The steps that must be taken to avoid similar kinds of security breach incident in the
future
C. The Incident Response Process:
The new Incident Response Process that would be implemented at Limetree encompasses a
number of procedures that will help to minimize the impact of the security incident and make a
solid recovery. The figure that has been highlighted below shows that a number of processes of
the response plan would be carried out interchangeably so that proper measures could be
introduced to deal with the security issue. After a security incident has been identified and
corrective actions have been taken, the recovery procedure must be initiated. As highlighted in
the figure, in case fresh malicious elements have been identified, the team can go back to the
containment stage so that suitable measures can be deployed to contain the extent of damage that
might be caused by the IT security breach incident.
The team would have to actively assess the Information Technology ecosystem of
Limetree so that it could be able to identify any kind of malicious behavior in its network or
system. All the phases of the Incident Recovery Plan must be followed in a disciplined manner.
The logging records must be critically analyzed to identify any potential security incident. IT
would help to classify the incident that could arise before the research and development entity
and compromise its security posture.
The IT staff members and personnel would be playing an active role throughout the
cybersecurity incident in the organizational setting of Limetree so that all traces of malicious
elements could be effectively identified and suitable actions could be taken against them.
Throughout the process, the roles of communication among the team members would be of
paramount importance. Such an approach would make sure that the proper flow of information
and details takes place among the organizational personnel on a real-time basis. The knowledge
5
ISE 510 6
of the professionals on the latest cybersecurity incidents must be upgraded on a regular basis so
that they could play an active role throughout the incident response process within Limetree Inc.
IV. Impact
A. Application
Limetree Inc. is a reliable research and development organization that conducts research
activities in various curing edge fields for both the federal government as well as private
corporations. As it has a close link with the federal government, and its research projects, the
R&D firm has to abide by the latest federal legislation as well as industrial regulations and
standards so that it can keep a robust security framework in place. There are a number of Acts
and laws that the organization must give special attention to so that a strong security posture can
be maintained. For instance, the business undertaking must comply with the Health Insurance
Portability and Accountability Act (HIPAA) which relates to data privacy and security
provisions. The objective is to safeguard the confidential medical information (Rouse &
Biscobing, 2019).
Limetree must also adhere to the Health Information Technology for Economic and Clinical
Health Act. This act was initiated to encourage the implementation of electronic health records
(EHR) and strengthen the use of technology in the United States of America. The HITECH Act
was introduced in the year 2009 so that the exchange of electronic protected health information
(ePHI) between hospitals, physicians and other bodies could be simplified (What is the HITECH
ACT?: What HITECH Compliance Means, 2019). Limetree Inc. has to ensure that the security
model that is implemented throughout the organization is in sync with the regulations and
legislation that exist in the industrial setting. The National Institute of Standards and Technology
(NIST) must be considered as the main body which would provide proper guidelines so that the
IT security infrastructure of the organization could be strengthened.
B. Impact
The regulations and industry standards that have been introduced by NIST would playa
vital role and help Limetree to strengthen the IT security framework of the organization. It must
make sure to adhere to NIST guidelines, HIPAA and HITECH so that the confidentiality and
integrity of the sensitive business information would not get compromised. The regulations
would basically guide the research and development firm to introduced robust and appropriate
security controls in place which could upgrade the effectiveness of the security system. The
inability to comply with the security legislation and standards would have a negative impact on
the business reputation of Limetree. In addition to this, legal action could be taken by its clients
in case a security breach incident is extremely serious in nature.
C. Financial and Legal Implications
The implications that Limetree Inc. would face if it fails to adhere to the regulations and a
security breach incident occurs would affect it legally and financially. The trustworthiness of the
business in the market environment could be adversely affected which would affect its credibility
before its clients and customers. If clients would lose trust, they would shift to Limetree’s
competitors and its profitability could drastically decline. In case Limetree gets involved in a
6
ISE 510 7
major security breach incident where confidential and highly sensitive information of the clients
gets leaked then it could be taken to the court of law.
V. Security Test Plan
The security test plan primarily captures the scope of the security test, the key resources
that would be used to strengthen the security posture of the organization. The resources that have
been highlighted in this section include the people resources. In addition to this, the hardware
and software of Limetree Inc. have also been captured as they make up the Information
Technology infrastructure of the organization. The special tools that would be required by the
ACME Cybersecurity, based on Limetree’s hardware and software have also been highlighted in
the security test plan.
A. Scope:
The scope of the project is to conduct a thorough assessment of the information security
system of Limetree Inc. so that the security breach incident can be evaluated. In order to carry
out a comprehensive check, there is the need to forensically analyze all the 250 computers that
are used in Limetree Inc. Based on the thorough analysis, suitable recommendations would be
made for the research and development business so that the security posture of its IT system can
be strengthened. The various risks and threats that the business undertaking is currently exposed
to because of its security loopholes will be identified and accordingly, a roust security model will
be planned for the firm.
The risk assessment will help Limetree to get an in-depth idea about the effectiveness or
ineffectiveness of the existing security approach. The ACME Cybersecurity Consulting Team
would enable the research and development entity to understand the IT vulnerabilities that exist
in the business undertaking which give an edge to cybercriminals and attackers. The security test
plan has been designed with the intention to identify the threats and vulnerabilities so that
suitable strategies can be introduced in order to mitigate the same. The team of experts that have
been hired would play a vital role to execute the project security plan. They would help to
develop robust secure network solutions, safeguard the firm’s confidential data and design
suitable cybersecurity strategies across the organization.
B. Resources:
People resources would be of chief importance to make sure that security issues, risks and
vulnerabilities in Limetree Inc. can be effectively identified and the overall quality of the
security posture can be strengthened.
Table 1
ACME Team Members - Titles and Roles
Team Member Title Role
7
ISE 510 8
Lead Cyber Security
Engineer
The role would include the development of secure network
solutions, performing network scans, conducting risk
assessments, and penetration testing. He would also manage
the firm’s security technology, implement the Security
Technical Implementation Guidelines (STIG) throughout the
entity.
Chief Information
Security Officer (CSO)
His primary responsibility is to safeguard Limetree’s data and
intellectual property. In addition to this, he has to strategize
and employ IT security strategies so that adequate security
could be given to the research and development business from
potential risks, threats, and cyberattacks.
Security Consultant He would be responsible to design effective cybersecurity
strategies across the Limetree organization.
C. Hardware and Software:
Currently, Limetree Inc. has in place numerous hardware and software that make up its
Information Technology ecosystem. The firm has a medium-sized network which enables it to
carry out the online activities. The key components of Limetree’s network include 250 desktops,
7 remotely manageable Cisco switches, 5 file and printer servers, 3 email servers, 3 web or
applications servers, 3 wireless access points, 3 firewall devices, 2 proxy servers, and 1 gateway
device to the internet (router).
The software or applications that are used in the research and development entity include
Google Chrome, Firefox, Internet Explorer, Microsoft Office, Adobe Flash, and Adobe Acrobat.
But there exists no standard browser that is used in the business environment. These browsers
even permit the remote installation of applets which impacts the security posture of the business.
The virus software that is employed in the business undertaking is MacAfee. It is locally
deployed on the computer systems of each and every user. The antivirus needs to be updated
every month mandatorily in all the systems of the organization.
The Structured Query Language (SQL) Database is used in the IT setting of Limetree. But
the total disk space for the SQL database log that is available is quite small. In fact, it is
overwritten with new information whenever it gets full.
D. Tools:
For conducting a thorough security test in Limetree Inc., the ACME team would require a
number of tools and resources so that a critical risk assessment procedure could be conducted
which would help to get an insight into the security posture of the research and development
organization. Firstly, a team of experienced and qualified IT professionals would be required so
that they could assess the existing IT ecosystem of the firm. At present, Limetree already has an
efficient Security Manager Jack Sterling. The team members would assist the firm’s Security
Manager so that a holistic risk assessment could be carried out. The tools that the specialized
team would need for conducting the risk assessment have been highlighted in the table.
8
ISE 510 9
Table 2
ACME – Software Resources for Breach Analysis
Software Description
Wireshark The free and open-source packet analyzer would be used for
various purposes such as network troubleshooting, software,
and communication protocol development, analysis, and
education. The data traffic could be effectively analyzed and
abnormal behavior could be identified.
Varonis Varonis is a robust security software platform that would help
to track, visualize, evaluate and safeguard the unstructured data
of Limetree.
Suricata Suricata is a fast open-source privacy breach detection
software that could perform intrusion detection on a real-time
basis.
VI. Risk Mitigation:
Risk mitigation is a vital strategy that would be necessary for Limetree Inc. so that it could
minimize the impact of threats and risks that could arise in its online setting. Suitable security
controls would be introduced which would ensure that similar breach incidents would not
reoccur in the future and compromise the security posture of the research and development
entity. Some of the core elements that have been captured in the section relates to security
controls, mitigation of vulnerabilities and evaluation of the effectiveness of the controls (Rouse
& Sullivan, 2019).
A. Security Controls at Limetree Inc:
1. Access control (for transmission medium) – Limetree must control the physical access
to the telecommunication medium by enclosing them in the rigid conduit that is sealed
with tamper-resistant epoxy and locking pull and drop boxes.
Risk – If a malicious actor were to get physical access to network cabling, they could
acquire unauthorized access and Limetree would never know without a physical
inspection or audit.
Impact – The most significant impact would be financial due to loss of contracts or
leaked proprietary information.
Likelihood – Low. Before implementing the recommended controls in this document,
there were many easier opportunities to exploit, and after Limetree implements this
control, a malicious actor would be detected due to the metal conduit encasing the
unencrypted cabling would obviously show the signs of tampering.
2. Awareness and Training (Security Awareness Training) – Limetree must provide
necessary training to the employees so that they would be aware of the basic security
elements. While making changes to the firm’s information system model, proper training
9
ISE 510
10
would be vital to make sure the personnel are skilled to identify any kind of abnormality
in the firm’s network (Nvd - Control - At-2 - Security Awareness Training, 2019).
Risk – In case any abnormal behavior would appear in the network, for example, receipt
of hundreds of spam emails, the employees could intimate the network administrator
about it so that appropriate actions could be taken.
Impact – The main impact on the human factors as they would be empowered to
strengthen the security posture of the business organization.
Likelihood – High. This control would be of paramount importance that could upgrade
the overall effectiveness of the security model of the entity.
3. Incident Response Control (Incident Reporting) – A proper reporting protocol must be
in place in Limetree so that the employees would be able to use them in case they come
across a possible security breach incident (Nvd - Control - At-2 - Security Awareness
Training, 2019).
Risk – The employees of Limetree would know the exact steps that they can take at the
individual level to report any suspected security incident to the firm’s incident response
capability. One of the main risks includes the receipt of suspicious or malicious
communication mails on a frequent basis.
Impact – This security control would impact the entire IT system of Limetree Inc. and
help to address formal incident reporting requirements as well as specific incident
reporting requirements.
Likelihood – High. The likelihood of introducing the security control is High in Limetree
Inc. as it could be well prepared to deal with any unpredictable security incident that
could arise at any time.
4. Physical and Environmental Protection Control – Limetree must design proper
procedures to facilitate the implementation of functional physical and environmental
protection rules so that the documents could be properly disposed of and unauthorized
personnel would not gain access into the office premises (Nvd - Control - At-2 - Security
Awareness Training, 2019).
Risk – No outsider or guests would be able to loiter inside the office premises. This
security control would help to ensure that such unprofessional behavior is controlled and
the official documents are safe from inaccessible to outsiders.
Impact – The control would have a direct impact on the human resources as they would
have to entertain outsiders such as clients and guests outside the office premises.
Likelihood – Moderate. The likelihood of introducing the control is moderate but it
would play a key role to strengthen the security infrastructure of Limetree.
5. Risk Assessment Control – Limetree must conduct a regular risk assessment of the IT
infrastructure so that it could get a detailed insight into the magnitude of harm from any
unauthorized users (Nvd - Control - At-2 - Security Awareness Training, 2019).
Risk – Any kind of threats or vulnerabilities that would exist in the IT setting of the
business undertaking could be identified. Thus, the scope of cyber hackers could be
restricted to a significant degree.
Impact – The impact of the security control would be technical in nature as the
assessment would inspect the IT infrastructure of the business entity.
Likelihood – High. The likelihood of the security control is high s it would enable
Limetree to conduct a thorough risk analysis to identify any kind of suspicious or
malicious activity within its organizational network.
10
ISE 510
11
6. Maintenance control – Limetree has to maintain the robust nature of the IT security so
that unauthorized actors would not get the chance to exploit the vulnerabilities of the
research and development entity (Nvd - Control - At-2 - Security Awareness Training,
2019).
Risk – The regular upgradation of antivirus would enable the strengthening of the IT
infrastructure and thus it could safeguard itself from infiltration by online hackers.
Impact – The impact would be financial in nature as Limetree Inc. would have to make
significant financial investments to upgrade, install and maintain the security level of the
IT system.
Likelihood – Moderate. The likelihood of implementing the maintenance control in the
organizational setting is moderate. This is because it could introduce more important
security measures in place to strengthen the IT security posture.
7. System and Information Integrity (Information System Monitoring) – Limetree Inc.
has to ensure that regular and timely Information System Monitoring is carried out so that
no abnormality could be ignored by the team (Nvd - Control - At-2 - Security Awareness
Training, 2019).
Risk – Any kind of attacks or potential attacks could be identified by introducing the
control relating to Information System Monitoring.
Impact – The impact of the security control would be technical as a thorough monitoring
process would be carried out in the technical environment of the organization.
Likelihood – Moderate. The likelihood of conducting the Information System
Monitoring is moderate as Limetree would have to implement other vital security
controls to strengthen its security posture.
8. Personnel Security Control (Access Agreements) – Limetree must make sure to
introduce access agreements with certain employees so that the accessibility of the
confidential information could be strengthened (NVD - Family - Personnel Security,
2019).
Risk – No unauthorized personnel would be able to gain entry into the location or the IT
folders where sensitive and confidential information has been stored. Prior approval
would be required from the respective managers for doing so.
Impact – The impact would be felt on the human factors as their accessibility in the
organizational setting would be restricted.
Likelihood – Moderate. There is a moderate likelihood of Limetree to introduce access
agreements so that the confidentiality of the data and information could be strengthened
(Force & Initiative, 2013).
B. Vulnerabilities:
The security controls that have been designed for Limetree Inc. would play a critical role to
strengthen the overall effectiveness of the measures that could be introduced to minimize the
extent of the harm or threat. For instance, the introduction of physical and environmental
protection policy would ensure that a professional and secure work environment can be
established where the internal business information would not be leaked to the outsiders.
Similarly, access control for transmission medium would prevent unauthorized access to
telecommunications lines so that the risk due to electronic eavesdropping can be reduced.
B. Evaluation:
11
ISE 510
12
A thorough assessment of the security controls is necessary to ensure they add value to the
quality of security of Limetree. A number of criteria must be introduced for measuring the
controls to make sure that they are properly implemented in the organizational setting. Limetree
Inc. organization must carefully review its telecommunication wiring diagrams, and carry out
tests to ensure that the telecommunications media is encased in rigid conduit which is sealed
with tamper-resistant epoxy and locking pull and drop boxes. Similarly, the CTV cameras must
be used to assess the office environment and ensure that no unauthorized individuals have been
given access to the office premises. Such evaluation techniques would help to ensure that the
security controls have been effectively implemented throughout Limetree Inc.
VII. Conclusion
A number of recommendations have been made for Limetree Inc. relating to the
administrative aspects, technical features, organizational personnel, and physical environment.
The objective is to help the research and development entity so that it can strengthen its security
infrastructure.
A. Administrative Recommendations – All the administrative and regulatory policies must
be designed in a simple and understandable manner so that the organizational personnel
of Limetree Inc. would be able to get a detailed insight into the actions or measures that
could be taken by them at the individual level to improve the effectiveness of the security
model. The guidelines must be able to convey the information relating to Limetree Inc.’s
security model with both technical as well as the non-technical audience. Frequent
workshops could be conducted so that all the administrative guidelines could be shared
with the employees of Limetree in a transparent manner.
B. Technical Recommendations – Limetree must deploy a robust Host Intrusion Detection
System (HIDS) so that it would be able to identify and block common attacks that could
arise in the online environment of the business undertaking. In the current times, cyber
attackers are using a broad range of sophisticated techniques to gain unauthorized access
into the networks of businesses (Intrusion Detection System (IDS) - GeeksforGeeks,
2019). So, Limetree could strengthen the IT security infrastructure and technical ability
by introducing the IDS which would enable the firm to monitor the online traffic that is
present in its network. The Network Administrator of the Research and Development
entity would also be able to receive alerts in case any suspicious or malicious activity has
been detected in its network or online infrastructure.
C. Personnel Recommendations – Technical training must be provided to the
organizational personnel of Limetree Inc. so that they would be well aware of the latest
security approaches and techniques. The organizational personnel are one of the most
vital parts of each and every business entity including Limetree Inc. They are also known
to be the weakest link when it comes to the security system of the IT ecosystem of an
organization. In the case of the Research and Development undertaking, there is the need
to ensure that the technical know-how and expertise of the organizational personnel is
constantly upgraded so that their basic awareness of IT security can be improved. Such a
step would be vital as it would empower the employees to take necessary action in case
any abnormal or suspicious behavior is observed in the network of the organization.
12
ISE 510
13
D. Physical Recommendations – Strict guidelines and rules need to be introduced in
Limetree Inc. relating to the work setting and the physical environment of the
organization. The management must ensure that outsiders, guests or unauthorized
individuals are not given access to enter the official premises where the employees carry
out the day to day official work. Such a step would be extremely vital to ensure that they
would not gain an access to confidential business information. The physical environment
in which the employees of Limetree operate must be thoroughly secured. The security
personnel must ensure that the official premises cannot be accessed by anyone other than
the current employees of the organization. Such a security measure would play a critical
role to safeguard the confidential and sensitive business information of Limetree Inc.
13
ISE 510
14
References
Blair, M. A. (2015). Computer Security Incident Response Plan. Retrieved October 12, 2019,
from https://www.cmu.edu/iso/governance/procedures/docs/incidentresponseplan1.0.pdf.
CRR Supplemental Resource Guide. (2019). Retrieved October 12, 2019, from https://www.us-
cert.gov/sites/default/files/c3vp/crr_resources_guides/CRR_Resource_Guide-IM.pdf.
Force, J. T., & Initiative, T. (2013). Security and privacy controls for federal information
systems and organizations.GNIST Special Publication,G800(53), 8-13.
Intrusion Detection System (IDS) - GeeksforGeeks. (2019).GGeeksforGeeks. Retrieved 12
October 2019, from https://www.geeksforgeeks.org/intrusion-detection-system-ids/
Nvd - Control - At-2 - Security Awareness TrainingG. (2019).GNvd.nist.gov. Retrieved 12 October
2019, from https://nvd.nist.gov/800-53/Rev4/control/AT-2
NVD - Family - Personnel SecurityG. (2019).GNvd.nist.gov. Retrieved 12 October 2019, from
https://nvd.nist.gov/800-53/Rev4/family/Personnel%20Security
Rouse, M., & Biscobing, J. (2019). What is HIPAA (Health Insurance Portability and
Accountability Act) ? - Definition from WhatIs.com. Retrieved October 12, 2019, from
https://searchhealthit.techtarget.com/definition/HIPAA.
Rouse, M., & Sullivan, E. (2019). What is risk mitigation? - Definition from WhatIs.com.
Retrieved October 12, 2019, from
https://searchdisasterrecovery.techtarget.com/definition/risk-mitigation.
What is the HITECH ACT?: What HITECH Compliance Means. (2019, September 16).
Retrieved October 12, 2019, from https://compliancy-group.com/what-is-the-hitech-act/
14
Students also viewed