1 / 22100%
When there is a suspected data breach, the course of action a chief
information security officer (CISO) should be analysing the situation and
making sure the correct tools and solutions are being implemented. Its
also very important to build the correct team and have ongoing reports
sent out. Management of data should be accessed again. Other data
systems should be restricted from being used and patches should be
resolved as well and real time analysis of the breach should be
completed as well. Depending on the data breach bases what type of
action to take. If the data is/was stolen, the contacting person associated
with the data should be contacted immediately. If its based on passwords
this could mean a key logger is being used so the keystrokes of
the keyboard should be checked. One data breach and steps to avoid
it would be phishing. Phishing is when someone sends a malicious
link in an email or installs malicious software. Steps to take would
to be to install an antivirus, or web filters can be used to block
malicious pages on the web. A lot of people aren't even sure of
what a CISO is being that it has only been around for the last
decade or so. A CISO is simply the senior level executive that
handles the execution and the overseeing of the company's cybersecurity
strategy. In case of a suspected data breach, the course of action of
the chief information security officer should take is first of all planning
for disaster recovery. Ensuring the privacy and security of customer data
is another strategy that will help in case of a data breach. Managing
responses to cybersecurity incidents and monitoring the IT environment
for vulnerabilities and abnormal events are also some great strategies
that a chief information security officer (CISO) can take in the case
of a suspected data breach. Developing secure business policies and
practices, hiring IT security staff, conducting employee security awareness
training, verifying the company’s compliance with laws and regulations
should also be some of the first things a CISO should look into
when possibly facing a suspected data breach.The type of data breach
affects the actions because it affects what needs to be done, it affects
your strategy. You wouldn't use the same strategy you used towards
identity theft when facing malware. In a scenario in which a data
breach occurs, the CISO would have to take action in order to in
best case scenario stop the information from getting into the hands of
the intended party. They would do this by increasing their responsibilities
and expanding their ow role within the company. Their first step would
be to stop the leak, by locating the source and containing it. They
would make sure that no more information is released as well as
take preventative measures against potential malware being installed on
the company’s data base. The organization targeted would be contacted
by the CISO to inform them of the breach and to also refresh them
on the correct procedures and protocols to handle the situation. Locking
down access to the network database will be crucial to access the
level of damage dealt. The security incident response team would be
next on the list to contact, they will be crucial to determine how
the attack was implemented, the amount of data leaked, what was
damaged, and which data was targeted. They will also investigate
suspicious behaviors of employees to help determine the parties involved
in the attack. After this the team and the CISO will put together
new software to prevent the attack from happening again. If a suspected
data breach were to take place, the CISO will be required to take
on additional roles and responsibilities in order to prevent the threat
from reaching its intended target or the loss of important data due
to damage or leaks. The CISO would first locate and contain the
threat, preventing it from accessing anymore files or data then it may
already have or releasing malware into the database. During this time,
the CISO should contact the organization to inform them of the possible
threat and refresh them on the approved protocol/steps that will take
place. The CISO should then temporarily lockdown any access to the
network database to determine how serious the threat may be and what
damage has been done already. The next step is to inform and update
the Security Incident Response Team about the situation. Together, the
team will gather data and information about how the breach was able
to slip through security, what data was targeted, damaged, leaked or
lost, employees data will be scanned for suspicious activity. The CISO
and their team will pick the threat apart to create a new software
that will be prepared for a similar attack and alert security before
the threat is able to access the database. In case of a suspected
data breach, the CISO should first secure the operation. By stabilizing
the whole operation, you are protecting any further data from being
stolen. The CISO should lock down all physical access points and
change all all access codes. The CISO Should also shutdown all
network connection temporarily, in case the source of the attack is
coming from the network. Once all of the area's of the operation has
been secured, The CISO should deploy Computer Security Incident
Response Team to help identify where the source of the breach
occurred. This team should be able monitor all networking traffic, all
source of communication, and other areas of vulnerability. Once, the
threat has been identified and neutralized, the CISO should look to
strengthen that area of weakness. Whether it's transferring all the sensitive
data to a more secure source, monitor network traffic stricter , granting
less access to important information, or installing IDS.The type of branch
effects this action because each threat needs to be handled in different
manner. If the threat is coming from an phishing email, then company
would have to start monitoring the companies email traffic and address
it company wide to prevent others from sending out information to a
malicious source.One type of data breach would be account hacking. A
few remedies for an account being hacked is to change the passwords
on the account, backup all sensitive data, or deactivate account/ start
a new account. In a case of a suspected data breach, the CISO
would first need to contain the threat without panic and with a quick
response time. After containing the threat they would need to see how
much they can retain that was not loss as they can, and shut down
the system and all servers. The next step would be to figure out if
the breach was internal or external and why the breach occurred.
However with different data breach's steps may change because if a
consumer information was hacked they would then need to get there
team to contact consumers. However some data breach's will be much
more serious with more extensive steps for example government top
secret information. A cloud data breach is far more damaging than a
regular computer, because multiple users information will be in the hands
of an attacker in single breach. Furthermore the same steps should be
taken, shut down system until the source of breach is found and
resolved. Most cloud data breach is due to the customers negligence .
If there was a data breach the CISO would first need to contain
the threat. Having an intrusion detection system would be beneficial to
minimize the amount of damage a breach could cause. Next, they
should shut down access to any compromised data/servers. The CISO
should know exactly what data or information was compromised and
what information was taken. They should deploy the disaster recovery
plan and team. The CISO should be aware if individual’s private
information was compromised and make appropriate notifications if so.
Depending on the type of breach the actions may not be as extensive
and time consuming. Some may be internal mistakes and the CISO
would have to adapt or make new policies and procedures for
employees. One example of a data breach could be caused by phishing.
You would need to identify where the email came from and who
opened it. Obtain a copy of said email as well. Ensure all employees
are aware of the phishing email, where it came from, and not to
open it. After it is contained and you have made sure there are no
longer any threats, you should have said employees change their
passwords. Provide further security training for employees. If I was
CISO and there was a security data breach first I must remember
not to panic. Second, I would identify that breach, contain the breach
before any more damages occurs. Then, I would create a team of
data analysts to identify the severity of the breach then create another
team to create a plan of action in case this were ever happen again.
There are many different types of data breaches that can affect the
action plan of the analysts. For example, when it comes to data
breaches there are some are intentional and unintentional once they
identify the right course of action for the breach. One of the most
common types of breaches is phishing. Phishing is when hackers create
a website that replicates a legit website and asking the user to login
into their account when in reality you have just given someone your
account information. The course of the action I would take is to
identify where the phishing raised from, second identify what was
affected; contain it and then create a plan of action on what to do
if the issue wherever to a raise. The role of the CISO is to
Establishing the right security and governance practices. Enabling a
framework for risk-free and scalable business operations. In case of a
data breach the chief information security officer should contain the
breach. If you react to a breach by panicking and reacting too
quickly, you could make some costly mistakes. Once you have determined
where the breach originated, it is crucial that you contain it. If the
breach spreads to other areas of your organization, it will become a
lot more difficult to handle. To reducing the risk of a data breach,
you need to understand where the risk is coming from. There are
two major risk factors, people and devices. A type of data breach
could be Malware. Malware is a common form of cybersecurity attacks.
They are a type of software that infects your entire system. They
are caused by tricking a user into clicking on something such as a
pop-up ad that leads to the download of the software onto the system.
This can lead to systems being severely slowed down, or completely
crashed. To prevent future attacks is remedy whatever caused the initial
breach to happen. Consult and understand what kind of protection you
need. The first thing a Chief information security officer should take
after a suspected data breach is to isolate the issue and make sure
it is contained. The next step is to shut down the network and
internal servers to make sure there are no other issues. After that
there should be some investigation done to determine what type of
data breach it was and how this affected the company assets.
For example, if there was a data breach that was the result of a
phishing scam it would be a high priority to educate employees and
make them more aware of security issues like malware/phishing scams.
Knowing about cyber attacks and preventative actions is meaningless
unless the information is shared with the rest of the company.
Just recently our company sent out a test phishing email to see if
employees would click on it. I would guess at least 25% of our
team clicked on it. Even with all of our continued education and
trainings around this and still this many employees fell for it. In
case of a suspected data breach, the course of action a chief
information security officer should take would be to have previously
implemented backup servers, or copies of important data for the
organization to continue operating if needed, but most importantly,
immediately turn off the power source to the computer, disconnect the
computer from the network, and/or reinstalling the systems application.
These steps to reacting to the security breach will minimize any
damage. The reaction time is crucial considering any breach so some
type intrusion detection system would be beneficial to detect abnormal
behavior within the network. This can help manage and automate security
reactions to intruders. Once the incident is under control, forensic security
team would investigate the incident. Documenting and identifying all
parties involved and how the security breach occurred, and the course
of action to resolved the issue. Depending on the type of breach, if
the organization’s security was compromised and couldn’t prevent further
damage to the data breach, some type of procedure or escalation for
this new type of breach would have to take place to find the
appropriate solution/course of action and be implemented for security
moving forward. If a data breach is suspected, the CISO’s response
time is critical due to longer the response time the higher possibility
of extensive damage occurring. Reacting to the incident involves the
anticipation of attacks as well as planning measures to be taken to
help restore the services. The incident is to be isolated by terminating
the power supply to the computer in question. The computer is to
be taken off the network to help reduce the chances of higher
damage, then the system applications are reinstalled as an attempt to
have the computer back to its proper operating condition. All data
breaches can not be reacted to in the same manner due to some
may be intentional while others may be accidental. Either way the use
of an antivirus and or an IDS can help monitor the network to
help reduce the chances of intentional attacks through the cyber domain.
When it comes to physical security using security password requirements
to access the data along with encryption are the best possibility. A
type of data breach would be a worm, these are the most used
type of malware that enters an operating system to spread malicious
code. It is self-replicating and consumes excessive bandwidth, deletes files,
or sends files through email which are infected. To reduce the risk
of a worm attack, the user account should be running as “limited”
to prevent installation, modification, or removal of software. Second
firewalls should limit unauthorized network activity with the operating
system set to automatically install system updates. Lastly, an anti-virus
software should be installed and set to scan and update automatically,
a paid for antivirus program will have more benefits and features in
comparison to a free program. In the case of a suspected breach, the
CISO should detect a breach fast and discover the details. Whenever
there is a breach, the CISO should be able to detect it at the
earliest, before it causes big damages to the organization. Next, the
CISO should assemble the team quickly, and prepare a plan to recover
from the breach. Whenever there is a cybersecurity breach, the CISO
should be able to assemble the Computer Security Incident Response
Team (CSIRT), and get a plan ready to tackle the cyber crisis,
gathering information for detailed analysis, ensuring involvement at all
levels. The next step would be to contain the breach effectively and
promptly. Once a breach is detected and the team is ready to tackle
it, the CISO should first seek to plan ways to contain it as
effectively as possible without losing any time. The CISO's role also
includes informing the public and customers. The CISO should also plan
to address the security issue with the public, especially since this is
an important step as regards mitigating damages caused by the incident.
Last, the CISO is responsible for taking steps to prevent further attacks.
Once a cybersecurity issue is detected and resolved, plans have to be
made and steps have to be taken to ensure that the same attack
wouldn't happen again and also ensure that other attacks are also
prevented.
In the event of a network-based breach, the CISO must make sure
that the incident response plan is in place, and limit the ability of
the attacker to access your network. This step includes blocking IP
addresses utilized by known threats or denying servers and critical
infrastructure the ability to directly communicate with the internet. The
next course of action would be to eliminate the files that caused the
infection, including removing the service/application that created the
vulnerability, and deleting or disabling the process/protocol used to launch
the cyber attack. The last course of action would be to remove
affected devices from the environment. This includes restoring affected
devices to a known-good state via backups or snapshots, and powering
off the device and disconnecting it from the network. In the case of
a suspected data breach the first thing the CISO should do is to
isolate the incident. After they have isolated the incident they should
try to prevent as much loss as possible. Then they need to investigate
what was taken in the breach. They then need to notify if any
personal information was taken from consumers. If found that the breach
was internal instead of external, they need to have the workers change
their passwords in order to protect from future attacks.
The CISO after knowing what type of breach has occurred if preventable
in the future should change policy in order to prevent future breaches.
If it were an external device that was the root cause having a
policy in place about personal drives in work computers would help
prevent future breaches. If it was a physical theft of information
making sure that updates are made to the security around that device
to prevent further thefts. If found to be an employee breach limiting
access to information that is not crucial to the job that they perform.
A CISO would and should isolate the breach and mitigate the damage
where possible. A CISO will also analyze the data breach after the
attack has been contained in order to assess why it occurred and
resolve any vulnerabilities found.
The type of data breach will determine what actions are taken. A
breach in Confidentiality can result in exposure to personal data. This
could be due to a lack of encryption use for storing and transmitted
data. The law requires for the organization to notify parties who were
exposed and mitigation of the risk in the future requires different
policies and technology. A breach in Integrity can result in data being
altered. The cause of this integrity breach can be the result of a
lack of anti-virus on computers or the lack of application/hardware
controls. The CISO would potentially have to find a means to restore
data that is damaged by the breach and mitigate any future risks by
installing controls mentioned earlier. A breach in Availability can result
in a loss of access to information resources. The CISO would have
to identify where and why the loss of access occurred and determine
if there is a redundant means to get users back online.
One specific course of action to mitigate a breach of Availability is
to create redundancies in your organizations infrastructure. This can be
done via the network or server level. For instance, an organization can
decide to have a primary and back up circuit connection to the
internet so that if one connection is lost then the back up kicks in.
For the perspective of the server, redundancy would translate into having
a RAID for your storage device. In the case of a suspected data
breach, a chief information security office has a few priorities: safety,
security, and awareness. Safety comes in the form of ensuring all
systems and people are safe from harm. Harm could be destruction of
property, acquired information endangering someone's physical safety, or
potential financial losses due to compromised information. Security requires
a CISO getting to the root of the breach, determining to what extent
the problem is, resolving up the problem, and placing in safeguards to
prevent such breaches from happening again. Awareness is alerting all
persons whose information could have been compromised. In some cases,
that's as simple as resetting all users' passwords. In other cases, the
remediation process is more complicated and requires more of a payout.
Different types of breaches (cyber, stolen paper receipts and banks
statements, recovered pin numbers and passcodes) require different
reactionary responses and carry different levels of responsibility. In the
case of a cyber data breach, a CISO would need to locate the entry
point into the system of the breach, sure up the system defenses and
install programs to prevent similar breaches, and send out virtual alerts
to all users on the platform to be aware and change passcodes. The
role of CISO is the overall management of security for the information
technology and report to the CEO of potential risk associated with
their information technology. The CISO will give out responsibilities to
handle the breach. In data breaches, the first thing is assess the
severity of the breach. Depending on the type of attack, they will
launch a counterattack plan. After they have taken action against the
attack, they will launch recovery actions to retrieve the loss of
information or analyze for any data corruption. At the end, they will
evaluate the cause of the breach and the monetary value of the attack
to the business. The CISO will have to implement the new findings
if any into the policies to prevent future similar breaches. They will
train the employees to the new procedures.
One type of breach is the Phising attacks. They are attacks that
imitate a legitimate site and trusted source created by hackers to trick
users into voluntarily inputting their sensitive information. They could ask
for usernames, passwords, or other information. The links could lead to
unknown sites that give hackers control of the information. They should
notify the information security teams so they are aware of the situation.
Another time sensitive step would be to run a full security scan on
the device used to catch lingering malware or intrusion of viruses that
could corrupt the data. Then the users must immediately change passwords
or information that was given out. If credit cards are compromised the
course of action is to cancel or change the cards. For SSN theft
notify the credit bureau to lock the SSN to avoid identity theft. The
next step is to evaluate the attack and the cost associated and conduct
proper training for future attacks. we have to understand that the reason
why we would expect the CISO to handle the suspected security
breach, is because he/she is the second at hand after the CEO. With
that being said normally the CISO would have various measures in
place to make sure this doesn't happen. In the case that it does
happen the CISO will have to gather is team together to pull the
data where the breach was formed. Advise all parties that were effected
by the breach and the measures that are to be taken to get it
under control.The type of breach varies widely based on the company
that it has effected. For example, credit card breach which holds a
lot of personal data can hit consumers the hardest causing them not
to have access to there funds when needed due to cards being locked
hoping to avoid fraud and identity theft. SOP's(Standard Operational
Procedures) if not already should be put into place so that everyone
will know how to handle these case as the come to surface. There
are many different types of data breaches. These range from stolen
information to DDoS. The most common types of data breaches and
one of the most important to protect against is stolen information. This
could include anything from stolen email addresses to passwords to
credit card information. Stolen information is one of the most devastating
types of data breaches that can happen to a company. This can have
a lasting impact on a company and could even send them out of
business and into bankruptcy. ransomware is another type of data
breaches that could happen to a company. This is when a company
is breached and their information on computers and servers is locked
and the only way to get it back is to pay the ransom fee. One
large data breach was back in 2014 when eBay was breached by
someone having access to 3 different coorperate employees credentials.
This allowed the breachers to have access to all of it's customers
personal information including emails, passwords, and other personally
identifiable information. eBay attempted to hide this but it was evenually
revealed that the hackers had access to the accounts for more than
229 days. This could have been avoided or at least noticed sooner
if eBay would have had better password renewal process. If an
organization has a data breach, a chief information security officer
(CISO) could take a few approaches, such as; engaging the incident
management team, as well as gaining an understanding of how the
breach took place. A large number of security breaches stem from
unintentional mistakes made by employee carelessness. If an employee is
not aware of the damage he or she can cause simply by opening
an email, and clicking on a link, there is not too much the company
can do about it. However, if the employee took the security training
and education where the harm of clicking on links and downloading
a worm, virus, or spyware was explained in detail, and the employee
electronically signed stating they agree with the information and the
repercussions involved, the organization can use that information in court
if the employee sued them. I work in a company that will not only
explain what the employee did wrong, it may include terminating the
employee for the action. The employee would typically retain a lawyer
and attempt to sue the organization for wrongful termination stating,
"they just did not know". The CISO and Human Resources (HR) could
bring that electronically signed paper to court, and most likely would
dismiss the accusation. A CISO should begin by first analyzing the
alert and determine if it’s a true attack. There are times when
someone could forget a password and used someone else’s login to
finish work or something to that effect. The CISO needs to notify
his response team and have them look to see if the attack is real
once that is determined then the following actions should be take place.
1. Shut off whatever they are using to access information
2. That means either unplugging hardware or executing a shut off
command
3. See what was taken and or damaged
4. Looking for where the leak is how it happen as well while
taking notes
5. Make a report of the incident and catalog all areas of vulnerability
6. Fix where the leak occurred and fortify security
7. Determine if it was an outside attack or fromwith in
8. Deal with the leak if its from within the company
9. Reset all users’ passwords and apply any needed restrictions
10. Notify public of information leak to save face and begin earning
back trust
11. Begin recovery and gaining back trust of those data that was
lost
There are several forms of data breach, like there are different ways
to rob a bank.
1. Employee error
2. The employee opened a phishing email or easy password
3. Cyber attack
4. Coming through internet links or searches using malware
5. Social engineering
6. Employees or other taking information from servers or other data
storage and then trading it to attackers or selling it on the
black-market, and or allowing someone inside that will attack the
organization
7. Unauthorized access
8. Someone allowed to wait at a desk or something akin to that,
they then look for things like personal Data and other HR
related items or attempt to steal company secrets
9. Ransomware
10. It is new but it attacks a company and stea lsdata or locks
out users and demands money to be removed, or information
regarding the decryption key
11. Malicious Insider
12. Someone actively plotting to either steal andor sabotage an
organization
13. Physical theft
14. They steal something
Each one requires a different response and different program to protect.
The bulk is done with physical security and monitoring as well as
cyber to prevent these attacks.
If an employee user information ever become vulnerable and taken the
following actgions need to occur. Immediate access denial and user
deleted then information gathered on what was stolen and taken and
determine if the employee did it on accident or purpose. Then notify
the CISO and being recovery protocols
In case of a suspected data breach, what course of action should
a chief information security officer (CISO) take?
When there is a security breach, it think that the CISO course of
action should be a few things. Building a team that can provide
security analysis who can provide analysis and assess vulnerabilities in
the infrastructure. A system engineering, who can perform security
monitoring. traffic analysis, intrusion detection. Also, installing antivirus
software should be installed, also, contacting the people who the data
breach affected.
How does the type of data breach affect the actions? yy
There are many causes for a data breach, it can affect a business,
whereas, if in the wrong hands,, it can cause the business to loose
financially. Also, if it is customer related, hackers can obtain personal
information from the customer. Personal information that is in the wrong
hands can cause identify theft.
Select 1 type of data breach and the course of action that should
be taken.
A data breach that comes to mind is human error. Sometimes humans
who are very busy can make common mistakes, like sending personal
information to a wrong party. Sometimes in human error, information
can be entered incorrectly as well., Leaving a computer unlocked can
cause someone to obtain information. Talking about a customer's
information or writing specific personal data down and not destroying it
can lead to a data breach. As we know that data breach is an
incident where information is stolen from a system without the knowledge
or authorization of the system's owner. Stolen data may involve sensitive,
proprietary, or confidential information such as credit card numbers,
customer data, trade secrets, pictures or matters of national security.
In this event, The CISO should make sure that all employees of the
organization change their passwords, assemble the team after the disaster
strikes to determine what went wrong in a breach, dealing with those
responsible if they're internal, and planning to avoid repeats of the
same crisis. Physical security is also a major concern. The statistics
discussed earlier reveal that the loss/theft of media such as laptops,
data cards, phones etc. account for major security breach incidents. Since
physical security breaches are the highest among personal devices,
individual users must be careful about securing their computing gadgets.
Data breaches are not always intentional. Users can accidentally send
protected data to the wrong email address or upload it to the wrong
share. Social engineering is very common way for data breach its a
manipulation technique that exploits human error to gain private
information, access, or valuables. In cybercrime, these scams tend to
lure unsuspecting users into exposing data, spreading malware infections,
or giving access to restricted systems. Attacks can happen online, in-
person, and via other interactions. Implementing security applies to any
database whether it was a personal computer or or a large corporation
and by applying the security steps ( precaution, maintenance, and
reaction) if there is a suspected data breach we would be in the
reaction step and the CISO would have to investigate what type of
threat it is and where exactly did it come from to provide the right
course of action, for example if it was internal and a mistake by
one of the employees a new measures of security needs to be
discussed and maybe more training for said employee.Of course the type
of threat would affect the action and the outcome, let say an
organization with a big number of personal data of costumers and the
breach was intended to steal personal info such as banking Info or
credit cards information, the organization would be responsible for any
damage to the costumers and would have to work on developing a
new security plan maybe adding more firewalls or changing anti viruses
as well as using IDS (Intrusion Detection Systems). In case of suspected
data breach, the CISO would gather his team together and have them
analyze the situation and determine if there are any immediate threats.
If a breach has occurred, then the CISO would set a plan into
action to seal off the breach, investigate how it happened and
communicate with the appropriate people about the incident. Once the
breach has been fixed and the investigation has been completed. The
CISO will develop a policy to prevent it from happening again.
Depending on the type of breach, that will determine the policy that
will be put into place. If it was an outside intrusion into the
network, then measure will be put in place to prevent that. That also
goes for user error or a user purposely attacking the company’s network
from the inside. If the breach was caused from an employee stealing
data. A policy can be put in place that would eliminate the use of
any type of electronic storage devices or cameras to prevent data being
taken out of the building. When reading over the chapter I think as
a chief information security officer is to first see how the breach
occurred. The breach could have happen by simply a worker placing
a flash drive in the computer and by them doing that the system
might have caught a virus. We offer see this when we are using
our bank cards and one minute is working and the next it has stop
working. Knowing how the breach happened helps to find where to
start. One solution that should take place is making sure that all
firewall are updated and is also Norton is used. The reason I said
Norton is because it does do a cleaning on the computer and system.
It is real important that the chief let the customer(s) know what is
going on and if their information has been compromised and what
action the company is taking to fix this issues. Giving the customer(s)
a firm solution and understand that this matter is important to the
company. I also think that the information should be back up on a
backup storage system. CISO is a management/leadership position in most
companies. It would NOT normally be the CISO that wades in and
assesses the damage, does forensic analysis, nor puts controls in place
to prevent further attacks. The CISO would set policy, advise, follow-
up, and consult.
Students also viewed