Breach Procedures: Who's on First?
Wed, 2008-03-05 04:01

Most larger businesses and many smaller organizations have now implemented specific policies and procedures setting forth the steps to be followed in the event of a security breach (e.g., composition of the response team, documentation requirements, procedures to be followed in making statements to the press, decision trees for issuing notices to consumers, etc.). One area, however, that is frequently overlooked is plain English instructions for rank-and-file employees to understand what a potential security breach looks like and how to report it. In recent experiences, we have found businesses well prepared to address a breach once it becomes aware of the problem, but the problem frequently takes too long to come to the attention of the right people within the organization. This has led companies to develop brief supplementary policies or guidances to educate employees concerning these issues.
The point is to make sure employees know what to look for (e.g., unusual activity on their workstations, a suspected compromise of a password and username, a lost USB fob, a stolen laptop, etc.) and to whom the matter should be reported. Because almost any employee may be in a position to observe a potential breach, most, if not all, employees should be educated on these issues. In this way, when suspicious activity occurs, employees will recognize it and promptly bring it to the attention of an appropriate manager. Given the range of laws requiring prompt reporting of breaches, ensuring this information gets to the right person in the organization as quickly as possible is critical. Implementing these types of policies or guidances will help establish the business was diligent in addressing the issue, guarantee management is promptly apprised of the problem, and minimize potential damages.

Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
WEBCAST
Gartner Video: Best Practices for Web Application Security and Compliance

Cenzic Faced with the growing threat of hacker attacks, how do you protect your data and your corporate reputation while increasing revenue?

» View this Webcast

WHITE PAPER
Email Continuity: Don't Know What You've Got Till it's Gone

MessageLabs Today, more email is being sent and attachment sizes are becoming larger. This means that security, archiving, and continuity systems must be able to scale easily. Learn to manage your email better…

» View this White Paper