Running Head: HANDLING THE SITUATION ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 1
IT 552 : Assignment 8-1
SNHU
HANDLING THE SITUATION ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 2
In order to handle the security incident involving the theft of the laptop
which contains at least 20 cases with Social Security numbers of people, there is the
need to follow a robust incident response life-cycle involving preparation, detection
and analysis, containment, eradication and recovery, and post-incident activity. It
would make sure that the extent of the damage could be mitigated and controlled to
the best possible extent (Cichonski et al., 2012, p 30). ab
The first step that must be taken is the enforcement of the physical device
security. It would make sure that even if the laptop is stolen, the sensitive
information cannot be assessed by the unauthorized party. Then the least privilege
policy must be introduced which would ensure that the access of sensitive
information and data could be kept under check. Then a communication pathway
must be established so that the security automation set-up could be initiated (How to
Securely Handle a Lost or Stolen Device: A Practical Workflow, 2019).
Examination of how data would be retrieved and/or destroyed
It is necessary to have a containment strategy in place so that the data that
was in the stolen laptop can be retrieved or destroyed based on the severity of the
situation. The most important aspect is decision-making i.e. whither to shut-down the
system or disable certain functions of the stolen laptop (Cichonski et al., 2012, p
44).
Some of the main criteria that must be kept in mind before recovering or
destroying the data include the potential damage and theft of the resource, the need
for preservation of evidence and time and resource needed to implement the suitable
strategy (Cichonski et al., 2012, p 46). In this case, since the information that has
been saved is sensitive and it relates to individuals who were being served by the
senior information security manager for a federal agency, the best thing to do is
HANDLING THE SITUATION ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 3
destroy the sensitive files and information. Eradication must be done in a phased
manner so that the remediation steps could be effectively taken (Cichonski et al.,
2012, p 47).
Determine the culprit
The culprit who has stolen the laptop can be identified by employing a
number of strategic approaches. For example, an incident database could be used to
gather information on real-time backlists. Similarly, the attacking host’s address can
be validated to get additional information on his online activity on the laptop
(Cichonski et al., 2012, p 46).
There is also the option to redirect the attacker or thief to a sandbox which is a
form of the containment strategy. It would help to monitor his activities and locate
him (Cichonski et al., 2012, p 44).
Committed security violations
A computer security threat is a violation of numerous computer security
policies, standard security protocols, and acceptable user policies. In this situation,
the security incident relates to the stealing of laptop from the workstation of a
senior information security manager of a federal agency is a major crime. This
various security standards and policies that have been violated include Acceptable
Use Policy (AUP), Access Control Policy (ACP), and Information Security Policy
(Hayslip, 2019).
Determination of steps to prevent similar incidents
In order to prevent similar security incidents from taking place in the near
future, it is necessary to follow a functional and robust security model. For instance,
there is the need to encrypt the hard drive so that no sensitive and confidential
information can be stolen even if the device has been stolen (Hayslip, 2019). In
HANDLING THE SITUATION ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 4
addition to this, there is also the need to maintain a back-up of sensitive information
so that the information will be readily available even though the laptop is not there.
There is a need to introduce a comprehensive laptop security policy so that the risk
of a breach can be effectively tackled (Hayslip, 2019).
Thus it is necessary to adopt a systematic and methodical approach so that the
security incident relating to the theft of laptop can be handled in the best possible
manner.
References
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security
incident handling guide. NIST Special Publication, 800(61), 1-147.
How to Securely Handle a Lost or Stolen Device: A Practical Workflow. (2019).
Retrieved 18 July 2019, from https://blog.rapid7.com/2017/11/09/how-to-securely-
handle-a-lost-or-stolen-device-a-practical-workflow/
Hayslip, G. (2019). 9 policies and procedures you need to know about if you’re
starting a new security program. Retrieved 18 July 2019, from
https://www.csoonline.com/article/3263738/9-policies-and-procedures-you-need-to-
know-about-if-youre-starting-a-new-security-program.html