Forensics and CSIRT
Name
Institution
SECURITY PLAN
Abstract.
CSIRT, commonly known as a Computer Security Incident Response Team, refers to an organization mandated with the responsibility of reviewing, receiving and correction of security incidence related to computers for governments, Corporate and religious institutions or even paid clients(Stein, 2009). This paper shows the forensics and CSIRT plan strategy for the organization.
Introduction.
Network administrators are given the responsibility to maintain computer networks. Security is an important requirement in the organizations systems, as these have an impact on day to day activities. Unauthorized access to organizations critical information is detrimental to its operations and could be used to cause the failure of the organization as a whole.
Basic risk assessment
The main risk facing the organization is the risk of access to organizations records and sensitive data by unauthorized persons. Confidentiality in information systems enables the limited access to documents and information. This is always ensured by the use of identification cards or passwords. The main methods of attack used are hacking and use of an insider in the organization. Main assets to be destroyed by unauthorized users are organizational data and destruction of organization copyrights and patents(Davis, 2011).
Proactive Security planning.
The organizations network administrator should therefor e ensures that known vulnerabilities are patched on hosts on a network that has no connection to any external network. This strategy enables detection of anything that may interfere with the smooth running of the network systems and control frequent system breakdowns. Policies to ensure that the organizations security system is effective include the use of passwords and strict administrative policies to ensure all the personnel are careful on information dissemination.
The floor plan of the target environment
Threats facing the organization, apart from unauthorized access into the organization system are such as cyber-attacks and the risk of losing funds to cyber criminals. These risks are both detrimental to the organization and should be looked into to ensure the continued profitability of the enterprise(Collen, G and Erika M, 2012). Current gaps include; untrustworthy employees and lack of skills to effect policies to protect the organizations security system. These vulnerability gaps should be looked into in order to affect necessary policies.
Emergency plans shouldbe put in place for both bomb threats and fire risks. In the case of bomb threats, organization personnel should be trained on the required response under such circumstances. In the case of a fire, extinguishers should be place in all strategic areas in the organization for higher safety levels. Files should be consistently backed up to ensure their ease in retrieval in case they are lost due to misplacements of theft in the organization. Monitoring the implementation of the security plan is critical to ensure all activities are well implemented and put into practice to achieve desired results.
Conclusion
Organization security is the most important element to ensure that the data, assets and critical areas in the organization are well protected and monitored. Finances should be set aside to ensure this area is not neglected and that the correct implementation of laid out plans is facilitated effectively and efficiently.
References
Colleen Garton & Erika McCulloch. (2012). Fundamentals of Technology Project Management. Chicago: MC Press.
Davis, G. (2011). IPad & iPhone administrator's guide: enterprise deployment strategies and security solutions. New York: McGraw-Hill.
Stein, R. J. (2009). Internet safety. New York: H.W. Wilson Co.