crisis-management planning every business should develop a security crisis-management team

8
CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team.

Upload: diane-golden

Post on 04-Jan-2016

214 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

CRISIS-MANAGEMENT PLANNING

Every business should develop a SecurityCrisis-Management team.

Page 2: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

The Team Handles Crisis Situations Such As:

Power Outages Flooding Earthquakes Storms Strikes Physical Break-Ins The Loss of Key Personnel

Page 3: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

Crisis-Management Team Questions:

What should the team do in response to theft of vital information?

How should they respond to a defacement of a website?

What actions should they take if the information system falls victim to a denial-of-service attack?

Page 4: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

Crisis-Management Team Actions:

Determine alternative actions. Involve law enforcement. Assist law enforcement. Evaluate the impact of the crisis. Find out value of everything lost. Notify key personnel of the

crisis. Execute emergency

management policies.

Page 5: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

DISASTER RECOVERY PLANNING

The ultimate security position is the organization’s ability to recover from a disaster.

Page 6: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

Disaster Recovery Plan:

A business impact assessment. Provisions for long-term crisis. A plan for off-site information

warehousing and backup. A plan for media types and access

methods required at the standby sites.

A reallocation of resources and the allocation of short-term personnel.

Page 7: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

EDUCATION AND MANAGEMENT

The CISO (Chief Information Security Officer) is in charge of an information security plan.

Develop the plan. Present the plan. Educate all parties involved. Handle law enforcement. Execute the plan.

Page 8: CRISIS-MANAGEMENT PLANNING Every business should develop a Security Crisis-Management team

CLASS QUESTION?

In disaster recovery planning, all are true except ______.

A) A business has an impact assessment.

B) A business has provisions for long-term crisis.

C) A business has a plan for off-site information warehousing.

D) A business has requirements for system upgrades.

D