Selecting Security Safeguards After a Customer PII Breach

Selecting Security Safeguards After a Customer PII Breach

Safeguards and Controls as Landoll (2016) points out are selected based on how effective they are in addressing the indicated security risk or as the author points out controls and safeguards are put in place to reduce the security risk. There are many approaches to handling safeguards and Landoll (2016) provides examples of five methods used in industry and is seen as solution sets.

Five Methods for Building a Solution Set

Method 1 is missing controls leads to implementing a safeguard. Method 2 is people, process and technology. The third method as Landoll (2016) points out is administrative, physical and technical. Method 4 is preventative, detective and correct. The last example of a method is available technology.

Any safeguard may address more than one threat and as Landoll (2016) and a solution set can be created for a vulnerability and sometimes can be a trial and error exercise to identify the correct mix for the solution set. Having a solution set or layers of security for each vulnerability assist in lowering risk.

People, Process and Technology Safeguards for PII

In the case of the breach of personally identifiable information (PII) that occurred, method 2, or people, process and technology would be best for safeguarding the PII. People safeguards would mean only allowing trusted or qualified individuals access to the PII. Process safeguards examples as Landoll (2016) points out are providing awareness training or putting account review processes around PII. The last safeguard is technology. Implementing a method of two-factor authentication or single sign-on when accessing PII or having intrusion detection systems or intrusion prevention systems in place to assist in safeguarding PII.

Cost-Benefit Analysis and Access Controls

Cost-benefit analysis is a method of to determine and compare the value and cost of a safeguard. The cost-benefit analysis provides a quantitative way to validate the control or safeguard that would be implemented.

A specific consideration with a trusted or qualified data access or access controls to PII would be creating a separate account for each trusted user to user for PII access outside of the usual account the trusted person users to handle daily activities. The access controls are enforcement mechanisms that determine whether an action is authorized to occur as Jacobs (2015) discusses. The access control methods determine what a user account can access. That separate account would require a more difficult password along with the two-factor authentication.

Implementing two-factor authentication and single sign-on would give a second level of authorization to prevent unauthorized access to PII, and single sign-on would assist in locking a insider threat out of the system quickly or if the account falls into a bad actor's hands also locking out that person.

Responding to the Breach

When a security risk to an organziations assest is found or know as described by Landoll (2016), the team of security assessors will develop recommendations to reduce the risks. These recommendations are referred to as a countermeasure or safeguard. The situation where a medium-size business has a security assesment completed and finds a vulnerable information leak of customer data and there has been a breach of the PII.

The first step in handling a PII beach is to identify with the medium-size business if the organzitation has an controls in place for incident response. If they are in place great but if not as Landoll (2016) suggest the organzations needs to quickly create an incident response plan that includes a checklist to assist in handling the incident or hiring a third part incident response team tocome in and assist if the organzation does not have the capability to handle the incident.

The Incident Response Process

There are many processes for handling Incident Response (IR). Peltier (2013) describes the typical incident response process as preparation, detection, incident analysis, incident containment, eradication, recovery, post-incident activity. Normally an internal team is identified and tools and resources are in place and ready to use for each step. Preparation, as described by Peltier (2013), is have a IR team in the organization ready and perform internal IR tests so that the team easily handles a real incident when it occurs. Detection is understanding signs of an incident before it occurs. Using monitoring tools is one way to detect. The incident analysis is understanding what normal patterns are in the environment or network to identify if an event is occurring. Incident containment is identifying an issue and understanding how best to surround the issue, so no other residual damage occurs. Eradication, as described by Peltier (2013), is how one recovers or cleans up from once the incident is contained. Sanitizing or rebuilding servers to eradicate the issue. Recovery is restoring the system or network back to its original state. An example of a recovery is putting a database system to a point and time to remove data integrity issues. The last step as discussed by Peltier (2013) is to hold a retrospective or post-incident analysis so that the process can be improved for the next response.

References

Jacobs, S. (2015). Engineering information security: The application of systems engineering concepts to achieve information assurance (2nd ed.). Wiley.

Landoll, D. (2016). The security risk assessment handbook (2nd ed.). CRC Press.

Peltier, T. R. (2013). Information security fundamentals (2nd ed.). CRC Press.

Posts in this series