SEC400 Managing Vulnerabilities
Managing Vulnerability
SEC400 Managing Vulnerability
Name
Class
Date
Professor
Managing Vulnerability
When a natural or manmade disaster or a technological threats occurs the effectiveness of the response will be crucial. While the disaster itself cannot be prepared for security personnel can have an effective response in place in the event a disaster or a technological threat was to occur. In a disaster or during technological threats security personnel fulfill the same role as when things are safe and secure. There role is to secure the person and property involved in the disaster or technological threat and to prevent loss. In order for security personnel to be effective in the event of a disaster there needs to be a disaster preparedness plan in place that includes preparing for technological threats as well as a disaster response plan in place.
The role of security personnel at a facility is to ensure the perimeter is properly secured and that there is no internal loss as well as in the new information security personnel are responsible for ensuring there are no security breaches to private sensitive data. Security personnel are responsible for patrolling the facility and protecting the people and the property but they are also responsible for ensuring vulnerabilities are minimized and in the event of a disaster or technological threat there is a proper response. In order to be effectively prepared in the event of a disaster or technological attack the security staff must be proactive in reducing potential vulnerabilities and managing the response.
The security personnel at a facility also have a responsibility to respond to any disasters that occur. Security personnel are responsible for securing the facility and guarding their property as well as providing assistance to staff members in need and support the responding agencies in any investigations. The security personnel will be responsible for implementing any emergency response plan and fulfilling the roles they have been assigned in the event of a disaster as well as providing the necessary assistance to responding agencies such as the police, fire, and medical personnel.
Disaster management is the process of addressing an event that has the potential to seriously disrupt the social fabric of the community and create security threats (Moon, 2011). The natural disaster can involve a hurricane, earthquake, flooding, tornadoes, tsunamis, and wildfires. The manmade disaster can evolve an event such as a nuclear accident or an act of violence by a terrorist group while the technological threat involves intrusion into the private information system of the government or an organization which not only threatens the organization but its employees and its customers. In order to manage the vulnerabilities associated with these events the necessary plans must be in place.
The disaster preparedness plan assists in creating a plan to prevent the disaster or to limits impact while technological threat preparedness’ plan ensure the organization or government infrastructure is not vulnerable to these threats. The first step for the organization, when creating the disaster preparedness plan, is to appoint an Emergency Management Coordinator. The Emergency Management Coordinator will lead the disaster preparedness plan. After appointing a team to assist in the emergency preparedness’ efforts the Emergency Management Coordinator will conduct an assessment of the potential security vulnerabilities faced by the facility in the event of a disaster to ensure these vulnerabilities can be minimized. Once potential vulnerabilities have been identified in the assessment the plan will include intimating the necessary improvements to reduce the security threat in the event of a disaster.
The emergency preparedness’ plan will include assigning the necessary security personnel their role in the event of a disaster and implementing the necessary drills and training to ensure security personnel will be effective in their roles in the event of a disaster. For example security personnel could be assignment to automatically secure the perimeter while other security staff members might be assigned to guarding sensitive information. The emergency preparedness’ plan will also outline the available resources and response agencies in the community that must be contacted for assistance in the event of a disaster.
Due to the new information age and the sensitive information that can be contained at a facility it is also essential that the facility have a technological threat response plan in order to protect sensitive data. The best way to protect sensitive data from threats is to develop a data security plan which includes first conducting an assessment of the information data security needs. Once the security needs have been identified a data security plan can be developed to ensure outside threats can be detected and thwarted.
The data security plan will include appointing only authorized personnel to access private company information and taking the necessary steps to protect the private data including the use of firewalls, implement network security with access controls, and encrypting sensitive data. Communication between remote users puts data at risk of being seen by outsiders (Norman, 2010). It is also essential that the facility has the necessary passwords and encryption software to prevent outside threats. Other countermeasures that will need to be put in place to prevent security threats are first ensuring that employees have been informed of company security polices and are in compliance with these policies.
When there is an emergency preparedness plan in place as well as a disaster response plan in place the facility can be better prepared in the event of a natural or manmade disaster or a technological threat. The key to dealing with intrusion threat actors is to detect them as early as possible and intercept them with a superior response before they can make their way to their intended target (Norman, 2010). The cost benefit of having these responses in place is unlimited. If the facility were to be destroyed by a natural disaster the financial burden could be in the hundreds of thousands but if some of the damage can be prevented due to emergency preparedness’ measures and an effective sensitive data security plan the amount of the cost incurred by the disaster could be limited.
The security countermeasures will ensure the facility is not vulnerable to cyber attacks that can result in the loss of sensitive information that includes the financial information of the company and private information of customer and employees. If the security at the facility is not able to ensure these threats are prevented then the loss could be huge. When information systems are intruded upon it could involve a malicious attack that takes the facility out of operation or the theft of sensitive information that could result in damage to the company’s reputation. In the Information age it is essential that security staff is capable of preventing technological attacks or threats.
The securities counter measures that will be implemented in the event of a natural disaster will ensure that the impact of the disaster is limited in order to reduce the costs associated with the event and will ensure that the appropriate response is in place to minimize the damage to the facility and its personnel. In the event of a disaster the facility and its property will be vulnerable to loss or damage that can result in a huge expense for the facility. The cost of implementing all of the necessary security measures to reduce vulnerabilities in the event of a disaster or technological threat will be less than $10,000 dollars while the cost for not being adequately prepared are countless.
Disaster risk management is essential to the effective response in any disaster. Sensible and cost effective risk reduction programs, such as early warning systems, strengthened building codes, and emergency preparedness strategies, are the best defense against future catastrophes (Moon, 2011). Since the attacks on 9/11 and the destruction associated with hurricane Katrina disaster risk management has become a common and necessary aspect for all organizations.
Recovery and operational backup plans will be developed in the emergency response plan and will include storing sensitive data in a separate secure location and storing physical assets in a fire proof safe. This will ensure the company’s operational systems are secure in the event of a disaster or an attack. In the event the facility is physically damage the security personnel will rely on the disaster response plan and wait for assistance for local response agencies. The role of security will be to secure the facility until help can arrive and provide support. The facility will need to have notification strategies in place to alert security staff of the disaster or the attack and establish a communication plan for the customer.
It can be difficult to evaluate the effectiveness of the security program for the disaster or the technological attack but in order to be able to determine the program’s success there must be an evaluation measure. In the natural or manmade disaster employee will be subject to random, unannounced security drills to ensure they are aware of the necessary response required in the event this situation were to occur. Information systems will be tested through the use of highly skilled IT personal continuously monitoring and assessing the effectiveness of the security measures.
References
McMillan, C. (2008). Natural Disasters: Prepare, Mitigate, And Manage. Retrieved September 30,
2012 from http://www.csa.com/discoveryguides/archives/ndht.php
Moon, B. (2011). What is Disaster Risk Reduction? Retrieved September 30, 2012 from
http://www.unisdr.org/who-we-are/what-is-drr
Norman, T. (2010). Physical Security Risk and Countermeasures: Effectiveness Metrics.
Retrieved September 30, 2012 from
http://www.csoonline.com/article/540063/physical-security-risk-and-countermeasures