Managing Catastrophic Loss of Sensitive Data: A Guide for IT and Security Professionals
Photopoulos, Constantine
In stock
Regular price
23.500 KD
inc. VAT
Couldn't load pickup availability
Table of contents
- Cover
- Authorv
- Contentsvii
- Chapter 1: Introduction1
- Overview2
- What Is Sensitive Data?3
- Personally Identifiable Information4
- Confidential Business Information4
- Data Categories5
- Data Security Breach5
- Data Loss Consequences6
- Impact6
- Identity Theft7
- Organizational Costs8
- Prevention and Safeguards9
- Response10
- Notification11
- Recovering from a Data Breach12
- Organization of the Book13
- Chapter 2: Data Classification13
- Chapter 3: Controls and Safeguards13
- Chapter 4: Data Security Policy13
- Chapter 5: Response Program14
- Chapter 6: Detection and Reporting14
- Chapter 7: Evaluation and Response14
- Chapter 8: Disclosure and Notification14
- Chapter 9: Closure14
- Appendix A: Relevant Legislation14
- Chapter 2: Data Classification15
- Introduction16
- Security Objectives16
- Potential Impact18
- Low18
- Moderate18
- High19
- Classification Levels19
- Confidential20
- Internal21
- Public21
- Data Ownership and Usage23
- Owner23
- Custodian24
- User25
- User Manager25
- Information Security Officer26
- Chief Information Officer26
- Data Sharing27
- Metadata27
- Classification Project28
- Create an Information Asset Inventory28
- Specify the Classification Criteria30
- Classify the Data31
- Special Considerations32
- Aggregation32
- Extracts32
- Impact on Other Data or Systems32
- Unstructured Data33
- Perform Risk Assessment33
- Assessment Elements34
- Models35
- Approach35
- Considerations36
- Risk Management Options37
- Key Practices37
- Documentation38
- Update38
- Challenges39
- Develop Control Implementation Plan39
- Types of Classification Level Controls40
- Device and Media Controls40
- Document Exceptions to Recommended Controls41
- The Data Life Cycle42
- Summary44
- Chapter 3: Controls and Safeguards47
- Data Security Program48
- Security Controls48
- Management Responsibility48
- Defense in Depth49
- Control Identification50
- Types of Controls51
- Baseline Approach51
- Constraints52
- Laptops53
- Portable Storage Devices54
- Transportable Media55
- E-mail56
- Internal Controls56
- External Controls57
- Technical Safeguards57
- Firewalls57
- Intrusion Detection and Prevention Systems58
- Penetration Testing and Vulnerability Scanning59
- Data Transmission60
- Remote Access60
- External System Connections61
- Antivirus and Patches62
- Isolation and Minimization62
- Access Control63
- Access Provisioning63
- Authentication63
- Entitlement Reviews65
- Privileged Accounts66
- Account Ownership66
- Account Assignment and Usage66
- Managing Account Passwords67
- Activity Logging and Monitoring67
- Policies and Procedures67
- Developer Access to Production68
- Physical Access69
- Activity Logging and Monitoring70
- Activity Monitoring70
- Baseline Logging71
- Centralized Log Management71
- Protection of Log Files72
- Storage72
- Software Assurance72
- Change Management74
- Backup and Restore75
- Disaster Recovery/Business Continuity Planning76
- Disposal77
- Measures78
- Responsibility78
- Recording78
- Insiders78
- Social Engineering80
- Third-Party Vendors81
- Training and Awareness83
- Compensating Controls85
- Auditing85
- Data Security Policy86
- Risk Assessment86
- Controls86
- Testing87
- Third Party Providers87
- Testing88
- Updating89
- Security Program89
- Controls89
- Summary90
- Chapter 4: Data Security Policy93
- Introduction94
- Standards and Procedures95
- Benefits95
- Goals and Trade-Offs96
- Tone and Perspective97
- Policy Development Process97
- Organize a Policy Development Team97
- Obtain Management Sponsorship and Approval98
- Outline Major Organizational Activities99
- Identify and Classify Data99
- Identify Threats99
- Determine Appropriate Controls99
- Develop the Policy100
- Obtain Needed Approvals100
- Contents100
- Statement of Purpose101
- Goals101
- Scope101
- Privacy Principles102
- Policy Statement103
- Data Classification104
- Data Ownership104
- Risk Assessment105
- Data Collection105
- Data Access105
- Transmission and Distribution106
- Data Transportation106
- Third-Party Use107
- Backup and Recovery107
- Disposal108
- Roles and Responsibilities108
- Organizational Management108
- Unit Management109
- Information Security Officer109
- Data Owner109
- Data Custodian109
- User109
- User Manager110
- Operations and Infrastructure110
- Development110
- Audit110
- Human Resources110
- Legal110
- General Responsibilities and Obligations111
- Reporting Data Security Breaches111
- Enforcement112
- Exceptions112
- Distribution113
- Contacts113
- Related Documents113
- Definitions114
- Acknowledgment114
- Related Policies114
- Policy Implementation117
- Update and Maintenance117
- Compliance Audit119
- Metrics119
- Management and Board Approval121
- Summary123
- Chapter 5: Response Program125
- Introduction126
- Objectives126
- Structure127
- Business Impact Analysis128
- Data Breach Response Team128
- Benefits129
- Organization130
- Team Members131
- Team Director131
- Functional Membership and Duties132
- Chief Security Officer133
- Chief Privacy Officer133
- Legal Counsel133
- Public Affairs134
- Human Resources134
- Chief Information Officer134
- Audit135
- Data Owner135
- Other Resources135
- Skills135
- External Expertise136
- Charter136
- Availability137
- Training137
- Team Support138
- Communications138
- Information Disclosure139
- Constituency Awareness139
- Funding140
- Outsourcing140
- Developing the Response Plan141
- Overview141
- Development142
- Approval143
- Audience143
- Contents143
- Strategies and Goals144
- Statement of Management Commitment144
- Data Breach Response Team144
- Contact Information145
- List of Critical Assets145
- Safeguards and Controls145
- Incident Types145
- Business Impact Analysis146
- Reporting Mechanisms and Guidelines146
- Information Disclosure146
- Severity Classification146
- Analysis and Assessment147
- Containment148
- Isolation148
- Recovery148
- Forensics149
- Disclosure and Notification149
- Communications150
- Documentation150
- Damage Assessment151
- Lessons Learned152
- Diagnosis Matrix152
- Vendor Contacts153
- Internal and External Resources153
- Related Documents153
- Future Roadmap153
- Update154
- Simulations and Walkthroughs154
- Summary156
- Chapter 6: Detection and Reporting159
- Incident Life Cycle160
- Detection160
- Party Responsible for Loss161
- System and Database Administrators162
- End Users164
- External Parties165
- Malicious Party166
- Antivirus Software166
- Intrusion Detection Systems167
- Firewalls169
- Honeypots170
- Audit Logs171
- Event Correlation172
- Variance from Baseline Profile172
- Multiple Steps173
- Reporting173
- Contacting the Response Team174
- Help Desk174
- Reporting Form175
- Initial Follow-Up176
- Summary177
- Chapter 7: Evaluation and Response179
- Introduction180
- Preliminary Determination180
- Initial Assessment181
- Team Escalation184
- Information Gathering185
- Party Responsible for Loss185
- Data Owners186
- System and Database Administrators186
- Network Administrators187
- End Users187
- Help Desk188
- Malicious Party188
- Intrusion Detection Systems188
- Log Analysis189
- Device-Based Information189
- Baselines and Variations190
- Root Causes190
- Classification190
- Scope191
- Length of Occurrence192
- Severity Assessment192
- Severity 1: Critical193
- Severity 2: Medium193
- Severity 3: Low194
- Need to Know194
- Response Approach194
- Containment195
- Criteria195
- Isolation195
- Other Measures197
- Powering Off Affected Systems197
- Disabling Services and Processes197
- Securing Access198
- Integrity Checks198
- Disabling Accounts198
- Enhancing Physical Security199
- Reconfiguring Detection Systems199
- Preserving Data and Logs199
- Recovery200
- Restoration200
- Monitoring201
- Data Compromise201
- System Compromise201
- Account Compromise202
- Identifying the Attacker202
- Documentation202
- Forensics204
- Summary206
- Chapter 8: Disclosure and Notification209
- Introduction210
- Notification Threshold211
- Identifying Notification Recipients213
- Timing214
- Source215
- Contents216
- Protection Recommendations217
- Offered Services218
- Credit Monitoring218
- Data Breach Monitoring219
- Identity Theft Insurance219
- Incentives219
- Method of Delivery219
- Other Notifications220
- Internal Disclosure221
- Regulatory Agencies222
- Law Enforcement223
- Media224
- Incident Reporting Agencies225
- Credit Reporting Agencies226
- Financial and Other Institutions226
- Other External Parties226
- Information Requests227
- Legal Issues and Requirements228
- Preparing for Follow-Up229
- Summary230
- Chapter 9: Closure233
- Introduction234
- Lessons Learned/Postmortem Meeting234
- Incident Impact and Costs237
- Overall Impact238
- Personnel Costs238
- Staff Productivity238
- Lost Revenue239
- Victim Notification239
- Victim Assistance239
- Call Center240
- Media Management240
- Consulting Services240
- Legal Fees240
- Regulatory or Legal Penalties240
- Reputational241
- Competitive Advantage241
- Credit Rating and Stock Price242
- New Controls and Safeguards242
- Root Cause Analysis242
- Corrective Action Plan242
- Internal and External Follow-Up244
- Closure Report245
- Preparation246
- Detection247
- Evaluation247
- Response247
- Closure248
- Summary250
- Appendix A: Relevant Legislation253
- Introduction254
- United States-Federal Legislation254
- Gramm-Leach-Bliley (GLB)254
- Health Insurance Portability and Accountability Act (HIPAA)256
- Sarbanes-Oxley Act (SOX)257
- Federal Information Security Management Act (FISMA)258
- United States-State Legislation259
- California259
- Other States260
- Arizona261
- Arkansas262
- Colorado262
- Connecticut263
- Delaware264
- District of Columbia264
- Florida265
- Georgia265
- Hawaii266
- Idaho266
- Illinois267
- Indiana267
- Kansas267
- Louisiana268
- Maine268
- Maryland269
- Massachusetts269
- Michigan270
- Minnesota270
- Montana271
- Nebraska271
- Nevada272
- New Hampshire272
- New Jersey273
- New York273
- North Carolina274
- North Dakota274
- Ohio275
- Oklahoma276
- Oregon276
- Pennsylvania277
- Rhode Island277
- Tennessee278
- Texas278
- Utah279
- Vermont279
- Washington280
- Wisconsin280
- Wyoming281
- Canada281
- Personal Information Protection and Electronic documents Act (PIPEDA)281
- European Union282
- Directive 95/46/EC282
- Index285
Book details
- Vendor Elsevier S & T
- SKU 9781597492393
- ISBN-13 9780080558714
- Author Photopoulos, Constantine
- Category Computers
- Subject General
Do you have questions about this book?
Offering a structured approach to handling and recovering from a catastrophic data loss, this book will help both technical and non-technical professionals put effective processes in place to secure their business-critical information and provide a roadmap of the appropriate recovery and notification steps when calamity strikes.
*Addresses a very topical subject of great concern to security, general IT and business management
*Provides a step-by-step approach to managing the consequences of and recovering from the loss of sensitive data.
*Gathers in a single place all information about this critical issue, including legal, public relations and regulatory issues
*Addresses a very topical subject of great concern to security, general IT and business management
*Provides a step-by-step approach to managing the consequences of and recovering from the loss of sensitive data.
*Gathers in a single place all information about this critical issue, including legal, public relations and regulatory issues
Instant delivery by email
Your access email arrives within minutes of checkout, with a sign-in link for each book — no shipping, no waiting.
Read on any device
Books open in VitalSource Bookshelf on your phone, tablet, or computer, online or offline. Your library is always available at aafaq.vitalsource.com — just log in with the email you used at checkout.
Lost the email?
Resend it to yourself in seconds from My eBook orders, or email cs@aafaqeducation.com and we'll help.