Managing Catastrophic Loss of Sensitive Data: A Guide for IT and Security Professionals

Photopoulos, Constantine

In stock
Regular price 23.500 KD inc. VAT
License
Table of contents
  • Cover
  • Authorv
  • Contentsvii
  • Chapter 1: Introduction1
  • Overview2
  • What Is Sensitive Data?3
  • Personally Identifiable Information4
  • Confidential Business Information4
  • Data Categories5
  • Data Security Breach5
  • Data Loss Consequences6
  • Impact6
  • Identity Theft7
  • Organizational Costs8
  • Prevention and Safeguards9
  • Response10
  • Notification11
  • Recovering from a Data Breach12
  • Organization of the Book13
  • Chapter 2: Data Classification13
  • Chapter 3: Controls and Safeguards13
  • Chapter 4: Data Security Policy13
  • Chapter 5: Response Program14
  • Chapter 6: Detection and Reporting14
  • Chapter 7: Evaluation and Response14
  • Chapter 8: Disclosure and Notification14
  • Chapter 9: Closure14
  • Appendix A: Relevant Legislation14
  • Chapter 2: Data Classification15
  • Introduction16
  • Security Objectives16
  • Potential Impact18
  • Low18
  • Moderate18
  • High19
  • Classification Levels19
  • Confidential20
  • Internal21
  • Public21
  • Data Ownership and Usage23
  • Owner23
  • Custodian24
  • User25
  • User Manager25
  • Information Security Officer26
  • Chief Information Officer26
  • Data Sharing27
  • Metadata27
  • Classification Project28
  • Create an Information Asset Inventory28
  • Specify the Classification Criteria30
  • Classify the Data31
  • Special Considerations32
  • Aggregation32
  • Extracts32
  • Impact on Other Data or Systems32
  • Unstructured Data33
  • Perform Risk Assessment33
  • Assessment Elements34
  • Models35
  • Approach35
  • Considerations36
  • Risk Management Options37
  • Key Practices37
  • Documentation38
  • Update38
  • Challenges39
  • Develop Control Implementation Plan39
  • Types of Classification Level Controls40
  • Device and Media Controls40
  • Document Exceptions to Recommended Controls41
  • The Data Life Cycle42
  • Summary44
  • Chapter 3: Controls and Safeguards47
  • Data Security Program48
  • Security Controls48
  • Management Responsibility48
  • Defense in Depth49
  • Control Identification50
  • Types of Controls51
  • Baseline Approach51
  • Constraints52
  • Laptops53
  • Portable Storage Devices54
  • Transportable Media55
  • E-mail56
  • Internal Controls56
  • External Controls57
  • Technical Safeguards57
  • Firewalls57
  • Intrusion Detection and Prevention Systems58
  • Penetration Testing and Vulnerability Scanning59
  • Data Transmission60
  • Remote Access60
  • External System Connections61
  • Antivirus and Patches62
  • Isolation and Minimization62
  • Access Control63
  • Access Provisioning63
  • Authentication63
  • Entitlement Reviews65
  • Privileged Accounts66
  • Account Ownership66
  • Account Assignment and Usage66
  • Managing Account Passwords67
  • Activity Logging and Monitoring67
  • Policies and Procedures67
  • Developer Access to Production68
  • Physical Access69
  • Activity Logging and Monitoring70
  • Activity Monitoring70
  • Baseline Logging71
  • Centralized Log Management71
  • Protection of Log Files72
  • Storage72
  • Software Assurance72
  • Change Management74
  • Backup and Restore75
  • Disaster Recovery/Business Continuity Planning76
  • Disposal77
  • Measures78
  • Responsibility78
  • Recording78
  • Insiders78
  • Social Engineering80
  • Third-Party Vendors81
  • Training and Awareness83
  • Compensating Controls85
  • Auditing85
  • Data Security Policy86
  • Risk Assessment86
  • Controls86
  • Testing87
  • Third Party Providers87
  • Testing88
  • Updating89
  • Security Program89
  • Controls89
  • Summary90
  • Chapter 4: Data Security Policy93
  • Introduction94
  • Standards and Procedures95
  • Benefits95
  • Goals and Trade-Offs96
  • Tone and Perspective97
  • Policy Development Process97
  • Organize a Policy Development Team97
  • Obtain Management Sponsorship and Approval98
  • Outline Major Organizational Activities99
  • Identify and Classify Data99
  • Identify Threats99
  • Determine Appropriate Controls99
  • Develop the Policy100
  • Obtain Needed Approvals100
  • Contents100
  • Statement of Purpose101
  • Goals101
  • Scope101
  • Privacy Principles102
  • Policy Statement103
  • Data Classification104
  • Data Ownership104
  • Risk Assessment105
  • Data Collection105
  • Data Access105
  • Transmission and Distribution106
  • Data Transportation106
  • Third-Party Use107
  • Backup and Recovery107
  • Disposal108
  • Roles and Responsibilities108
  • Organizational Management108
  • Unit Management109
  • Information Security Officer109
  • Data Owner109
  • Data Custodian109
  • User109
  • User Manager110
  • Operations and Infrastructure110
  • Development110
  • Audit110
  • Human Resources110
  • Legal110
  • General Responsibilities and Obligations111
  • Reporting Data Security Breaches111
  • Enforcement112
  • Exceptions112
  • Distribution113
  • Contacts113
  • Related Documents113
  • Definitions114
  • Acknowledgment114
  • Related Policies114
  • Policy Implementation117
  • Update and Maintenance117
  • Compliance Audit119
  • Metrics119
  • Management and Board Approval121
  • Summary123
  • Chapter 5: Response Program125
  • Introduction126
  • Objectives126
  • Structure127
  • Business Impact Analysis128
  • Data Breach Response Team128
  • Benefits129
  • Organization130
  • Team Members131
  • Team Director131
  • Functional Membership and Duties132
  • Chief Security Officer133
  • Chief Privacy Officer133
  • Legal Counsel133
  • Public Affairs134
  • Human Resources134
  • Chief Information Officer134
  • Audit135
  • Data Owner135
  • Other Resources135
  • Skills135
  • External Expertise136
  • Charter136
  • Availability137
  • Training137
  • Team Support138
  • Communications138
  • Information Disclosure139
  • Constituency Awareness139
  • Funding140
  • Outsourcing140
  • Developing the Response Plan141
  • Overview141
  • Development142
  • Approval143
  • Audience143
  • Contents143
  • Strategies and Goals144
  • Statement of Management Commitment144
  • Data Breach Response Team144
  • Contact Information145
  • List of Critical Assets145
  • Safeguards and Controls145
  • Incident Types145
  • Business Impact Analysis146
  • Reporting Mechanisms and Guidelines146
  • Information Disclosure146
  • Severity Classification146
  • Analysis and Assessment147
  • Containment148
  • Isolation148
  • Recovery148
  • Forensics149
  • Disclosure and Notification149
  • Communications150
  • Documentation150
  • Damage Assessment151
  • Lessons Learned152
  • Diagnosis Matrix152
  • Vendor Contacts153
  • Internal and External Resources153
  • Related Documents153
  • Future Roadmap153
  • Update154
  • Simulations and Walkthroughs154
  • Summary156
  • Chapter 6: Detection and Reporting159
  • Incident Life Cycle160
  • Detection160
  • Party Responsible for Loss161
  • System and Database Administrators162
  • End Users164
  • External Parties165
  • Malicious Party166
  • Antivirus Software166
  • Intrusion Detection Systems167
  • Firewalls169
  • Honeypots170
  • Audit Logs171
  • Event Correlation172
  • Variance from Baseline Profile172
  • Multiple Steps173
  • Reporting173
  • Contacting the Response Team174
  • Help Desk174
  • Reporting Form175
  • Initial Follow-Up176
  • Summary177
  • Chapter 7: Evaluation and Response179
  • Introduction180
  • Preliminary Determination180
  • Initial Assessment181
  • Team Escalation184
  • Information Gathering185
  • Party Responsible for Loss185
  • Data Owners186
  • System and Database Administrators186
  • Network Administrators187
  • End Users187
  • Help Desk188
  • Malicious Party188
  • Intrusion Detection Systems188
  • Log Analysis189
  • Device-Based Information189
  • Baselines and Variations190
  • Root Causes190
  • Classification190
  • Scope191
  • Length of Occurrence192
  • Severity Assessment192
  • Severity 1: Critical193
  • Severity 2: Medium193
  • Severity 3: Low194
  • Need to Know194
  • Response Approach194
  • Containment195
  • Criteria195
  • Isolation195
  • Other Measures197
  • Powering Off Affected Systems197
  • Disabling Services and Processes197
  • Securing Access198
  • Integrity Checks198
  • Disabling Accounts198
  • Enhancing Physical Security199
  • Reconfiguring Detection Systems199
  • Preserving Data and Logs199
  • Recovery200
  • Restoration200
  • Monitoring201
  • Data Compromise201
  • System Compromise201
  • Account Compromise202
  • Identifying the Attacker202
  • Documentation202
  • Forensics204
  • Summary206
  • Chapter 8: Disclosure and Notification209
  • Introduction210
  • Notification Threshold211
  • Identifying Notification Recipients213
  • Timing214
  • Source215
  • Contents216
  • Protection Recommendations217
  • Offered Services218
  • Credit Monitoring218
  • Data Breach Monitoring219
  • Identity Theft Insurance219
  • Incentives219
  • Method of Delivery219
  • Other Notifications220
  • Internal Disclosure221
  • Regulatory Agencies222
  • Law Enforcement223
  • Media224
  • Incident Reporting Agencies225
  • Credit Reporting Agencies226
  • Financial and Other Institutions226
  • Other External Parties226
  • Information Requests227
  • Legal Issues and Requirements228
  • Preparing for Follow-Up229
  • Summary230
  • Chapter 9: Closure233
  • Introduction234
  • Lessons Learned/Postmortem Meeting234
  • Incident Impact and Costs237
  • Overall Impact238
  • Personnel Costs238
  • Staff Productivity238
  • Lost Revenue239
  • Victim Notification239
  • Victim Assistance239
  • Call Center240
  • Media Management240
  • Consulting Services240
  • Legal Fees240
  • Regulatory or Legal Penalties240
  • Reputational241
  • Competitive Advantage241
  • Credit Rating and Stock Price242
  • New Controls and Safeguards242
  • Root Cause Analysis242
  • Corrective Action Plan242
  • Internal and External Follow-Up244
  • Closure Report245
  • Preparation246
  • Detection247
  • Evaluation247
  • Response247
  • Closure248
  • Summary250
  • Appendix A: Relevant Legislation253
  • Introduction254
  • United States-Federal Legislation254
  • Gramm-Leach-Bliley (GLB)254
  • Health Insurance Portability and Accountability Act (HIPAA)256
  • Sarbanes-Oxley Act (SOX)257
  • Federal Information Security Management Act (FISMA)258
  • United States-State Legislation259
  • California259
  • Other States260
  • Arizona261
  • Arkansas262
  • Colorado262
  • Connecticut263
  • Delaware264
  • District of Columbia264
  • Florida265
  • Georgia265
  • Hawaii266
  • Idaho266
  • Illinois267
  • Indiana267
  • Kansas267
  • Louisiana268
  • Maine268
  • Maryland269
  • Massachusetts269
  • Michigan270
  • Minnesota270
  • Montana271
  • Nebraska271
  • Nevada272
  • New Hampshire272
  • New Jersey273
  • New York273
  • North Carolina274
  • North Dakota274
  • Ohio275
  • Oklahoma276
  • Oregon276
  • Pennsylvania277
  • Rhode Island277
  • Tennessee278
  • Texas278
  • Utah279
  • Vermont279
  • Washington280
  • Wisconsin280
  • Wyoming281
  • Canada281
  • Personal Information Protection and Electronic documents Act (PIPEDA)281
  • European Union282
  • Directive 95/46/EC282
  • Index285
Book details
  • Vendor Elsevier S & T
  • SKU 9781597492393
  • ISBN-13 9780080558714
  • Author Photopoulos, Constantine
  • Category Computers
  • Subject General

Do you have questions about this book?

Ask an expert!

Offering a structured approach to handling and recovering from a catastrophic data loss, this book will help both technical and non-technical professionals put effective processes in place to secure their business-critical information and provide a roadmap of the appropriate recovery and notification steps when calamity strikes.

*Addresses a very topical subject of great concern to security, general IT and business management
*Provides a step-by-step approach to managing the consequences of and recovering from the loss of sensitive data.
*Gathers in a single place all information about this critical issue, including legal, public relations and regulatory issues