Running Head: HANDLING THE SITUATION ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac 1
IT 552 : Assignment 8-1
HANDLING THE SITUATION ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 2
In order to handle the security incident involving the theft of the laptop which
contains at least 20 cases with Social Security numbers of people, there is the need
to follow a robust incident response life-cycle involving preparation, detection and
analysis, containment, eradication and recovery, and post-incident activity. It would
make sure that the extent of the damage could be mitigated and controlled to the
best possible extent (Cichonski et al., 2012, p 30). ac
The first step that must be taken is the enforcement of the physical device
security. It would make sure that even if the laptop is stolen, the sensitive
information cannot be assessed by the unauthorized party. Then the least privilege
policy must be introduced which would ensure that the access of sensitive information
and data could be kept under check. Then a communication pathway must be
established so that the security automation set-up could be initiated (How to Securely
Handle a Lost or Stolen Device: A Practical Workflow, 2019).
Examination of how data would be retrieved and/or destroyed
It is necessary to have a containment strategy in place so that the data that
was in the stolen laptop can be retrieved or destroyed based on the severity of the
situation. The most important aspect is decision-making i.e. whither to shut-down the
system or disable certain functions of the stolen laptop (Cichonski et al., 2012, p 44).
Some of the main criteria that must be kept in mind before recovering or
destroying the data include the potential damage and theft of the resource, the need
for preservation of evidence and time and resource needed to implement the suitable
strategy (Cichonski et al., 2012, p 46). In this case, since the information that has
been saved is sensitive and it relates to individuals who were being served by the
senior information security manager for a federal agency, the best thing to do is
destroy the sensitive files and information. Eradication must be done in a phased
HANDLING THE SITUATION ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 3
manner so that the remediation steps could be effectively taken (Cichonski et al.,
2012, p 47).
Determine the culprit
The culprit who has stolen the laptop can be identified by employing a
number of strategic approaches. For example, an incident database could be used to
gather information on real-time backlists. Similarly, the attacking host’s address can
be validated to get additional information on his online activity on the laptop
(Cichonski et al., 2012, p 46).
There is also the option to redirect the attacker or thief to a sandbox which is a
form of the containment strategy. It would help to monitor his activities and locate
him (Cichonski et al., 2012, p 44).
Committed security violations
A computer security threat is a violation of numerous computer security
policies, standard security protocols, and acceptable user policies. In this situation, the
security incident relates to the stealing of laptop from the workstation of a senior
information security manager of a federal agency is a major crime. This various
security standards and policies that have been violated include Acceptable Use Policy
(AUP), Access Control Policy (ACP), and Information Security Policy (Hayslip,
2019).
Determination of steps to prevent similar incidents
In order to prevent similar security incidents from taking place in the near
future, it is necessary to follow a functional and robust security model. For instance,
there is the need to encrypt the hard drive so that no sensitive and confidential
information can be stolen even if the device has been stolen (Hayslip, 2019). In
addition to this, there is also the need to maintain a back-up of sensitive information
HANDLING THE SITUATION ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 4
so that the information will be readily available even though the laptop is not there.
There is a need to introduce a comprehensive laptop security policy so that the risk
of a breach can be effectively tackled (Hayslip, 2019).
Thus it is necessary to adopt a systematic and methodical approach so that the
security incident relating to the theft of laptop can be handled in the best possible
manner.
References
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security
incident handling guide. NIST Special Publication, 800(61), 1-147.
How to Securely Handle a Lost or Stolen Device: A Practical Workflow. (2019).
Retrieved 18 July 2019, from https://blog.rapid7.com/2017/11/09/how-to-securely-
handle-a-lost-or-stolen-device-a-practical-workflow/
Hayslip, G. (2019). 9 policies and procedures you need to know about if you’re
starting a new security program. Retrieved 18 July 2019, from
https://www.csoonline.com/article/3263738/9-policies-and-procedures-you-need-to-
know-about-if-youre-starting-a-new-security-program.html