Question

In: Operations Management

In the context of ABC Inc., which is a large on-line electronic product company, answer the...

In the context of ABC Inc., which is a large on-line electronic product company, answer the following questions.

  1. State three regulations and standards that it should comply with.
  2. List the responsibilities (role) of Information Security Officer in ABC Inc.
  3. Suggest a reporting structure (as a diagram) for ABC Inc., assuming it has 2 million customers, 2000 employees, approximately 20000 transactions each day, and $2 billion sales. Give a brief justification.
  4. Describe an incident response plan for ABC Inc. Write it as a list of steps with a brief description for each.

Solutions

Expert Solution

1. Regulations and Standards

Regulations

Businesses engaging in e-commerce are required to provide certain details on their websites in accordance with the Electronic Commerce Regulations. They should also be aware of their duties under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013. The information that must be provided includes:

  • details about your business
  • goods and/or services which are being sold and pricing
  • payment and delivery arrangements
  • the right of the consumer to cancel their contract within a specified time
  • if applicable, details of the trader’s complaints handling policy
  • where applicable, any compatibility of digital content with hardware or software

Customers have the right to cancel their contract within 14 calendar days - this is commonly referred to as a 'cooling off period'. This applies even if services have commenced in the cooling off period. Cancellation must be in a prescribed form. There is an exception for digital content if the customer acknowledges the loss of the right to cancel.

Standards

Standards are instructions, specifications or measurements that serve as specific benchmarks for expected normal practices in an organization. In general, a standard is a reference point, model, or rule for implementing practices or procedures and for evaluating results.

In essence, a standard is an agreed way of doing something. It could be about making a product, managing a process, delivering a service or supplying materials standards can cover a huge range of activities undertaken by organizations and used by their customers.

2. Role of Information Security Officer in ABC Inc.

Information security officers monitor the organization's IT system to look for threats to security, establish protocols for identifying and neutralizing threats, and maintain updated anti-virus software to block threats. They are responsible for setting the computer usage protocols for their organization, for facilitating training on minimizing threats to the IT system, and for determining which types of software the organization should use. Information security analysts investigate cases where the IT system has been compromised and take the appropriate action to resolve the problem. Information security analysts work in both the public and the private sectors. Since the nature of their work involves working with computer systems, they work in clean, climate-controlled environments and must be able to sit for long periods of time.

3. Reporting Structure for ABC Inc.

4.Incident Response Plan for ABC Inc.

An incident response plan should be set up to address a suspected data breach in a series of phases. Within each phase, there are specific areas of need that should be considered.
The incident response phases are:

  1. Preparation
  2. Identification
  3. Containment
  4. Eradication
  5. Recovery
  6. Lessons Learned

1. Preparation

This phase will be the work horse of your incident response planning, and in the end, the most crucial phase to protect your business. Part of this phase includes:

  • Ensure your employees are properly trained regarding their incident response roles and responsibilities in the event of data breach
  • Develop incident response drill scenarios and regularly conduct mock data breaches to evaluate your incident response plan.
  • Ensure that all aspects of your incident response plan (training, execution, hardware and software resources, etc.) are approved and funded in advance

2. Identification

This is the process where you determine whether you’ve been breached. A breach, or incident, could originate from many different areas.

Questions to address

  • When did the event happen?
  • How was it discovered?
  • Who discovered it?
  • Have any other areas been impacted?
  • What is the scope of the compromise?
  • Does it affect operations?

3. Containment

When a breach is first discovered, your initial instinct may be to securely delete everything so you can just get rid of it. However, that will likely hurt you in the long run since you’ll be destroying valuable evidence that you need to determine where the breach started and devise a plan to prevent it from happening again.

Questions to address

  • What’s been done to contain the breach short term?
  • What’s been done to contain the breach long term?
  • Has any discovered malware been quarantined from the rest of the environment?
  • What sort of backups are in place?

4. Eradication

Once you’ve contained the issue, you need to find and eliminate the root cause of the breach. This means all malware should be securely removed, systems should again be hardened and patched, and updates should be applied.
Whether you do this yourself, or hire a third party to do it, you need to be thorough. If any trace of malware or security issues remain in your systems, you may still be losing valuable data, and your liability could increase.
Questions to address

  • Have artifacts/malware from the attacker been securely removed?
  • Has the system be hardened, patched, and updates applied?
  • Can the system be re-imaged?

5. Recovery

This is the process of restoring and returning affected systems and devices back into your business environment. During this time, it’s important to get your systems and business operations up and running again without the fear of another breach.

Questions to address

  • When can systems be returned to production?
  • Have systems been patched, hardened and tested?
  • Can the system be restored from a trusted back-up?
  • How long will the affected systems be monitored and what will you look for when monitoring?
  • What tools will ensure similar attacks will not reoccur? (File integrity monitoring, intrusion detection/protection, etc)

6. Lessons Learned

Once the investigation is complete, hold an after-action meeting with all Incident Response Team members and discuss what you’ve learned from the data breach. This is where you will analyze and document everything about the breach. Determine what worked well in your response plan, and where there were some holes. Lessons learned from both mock and real events will help strengthen your systems against the future attacks.

Questions to address

  • What changes need to be made to the security?
  • How should employee be trained differently?
  • What weakness did the breach exploit?

Related Solutions

ABC Co, a large stock-exchange-listed company, is evaluating an investment proposal to manufacture Product WWW, which...
ABC Co, a large stock-exchange-listed company, is evaluating an investment proposal to manufacture Product WWW, which has performed well in test marketing trials conducted recently by the company’s research and development division. Product WWW will be manufactured using a fully-automated process which would significantly increase noise levels from ABC Co’s factory. The following information relating to this investment proposal has now been prepared: PAGE 10 OF 13 Initial investment RM 2 million Selling price (current price terms) RM 20 per...
ABC Company is considering adding a new line to its product mix, and the capital budgeting...
ABC Company is considering adding a new line to its product mix, and the capital budgeting analysis is being conducted by Jameel, a recently graduated MBA. The production line would be set up in unused space in the main plant. The machinery’s invoice price would be approximately Rs 5,000,000, another Rs 250,000 in shipping charges would be required, and it would cost an additional Rs 750,000 to install the equipment. The machinery has an economic life of 4 years, and...
CVP – ABC Company The following information pertains to ABC Company and its product – Product...
CVP – ABC Company The following information pertains to ABC Company and its product – Product Z: Selling Price per unit. $45.00 Direct Material Cost per kg $2.00 Direct Labour Cost per unit $1.20 Variable Overhead cost per unit $0.80 Material required per unit. 2KGS Other variable expenses per unit. $0.60 Annual Fixed Costs: Advertising. $15,000 Fixed Manufacturing. $60,000 Other Fixed Expenses. $8,000 Required: What is the Breakeven Point in both units and sales dollars? For this you will need...
ABC discount store has the following product line in its product line; toys, apparels, kitchenware, food,...
ABC discount store has the following product line in its product line; toys, apparels, kitchenware, food, jewelry, furniture, health and fitness, consumer electronics, Giftware and Fashion Apparel. The annual demand of toys segment is 48000 units. The average lead time is 4 weeks. The standard deviation of demand during the average lead time is 75 units / week. The cost of ordering is Rs. 400 per order. The cost of purchase of the product is Rs. 10 per unit. The...
subject: financial management ABC Company is considering adding a new line to its product mix, and...
subject: financial management ABC Company is considering adding a new line to its product mix, and the capital budgeting analysis is being conducted by Jameel, a recently graduated MBA. The production line would be set up in unused space in the main plant. The machinery's invoice price would be approximately Rs 5,000,000, another Rs 250,000 in shipping charges would be required, and it would cost an additional Rs 750,000 to install the equipment. The machinery has an economic life of...
Case: ABC Corp. International Company, a manufacturer of medical device, assembles a particular product line at...
Case: ABC Corp. International Company, a manufacturer of medical device, assembles a particular product line at a wholly owned facility in Singapore. The product is designed at XYZ’s headquarters in the United States, but the different components used in the assembly process are manufactured throughout Asia and shipped to Singapore for final assembly. Some of the components are manufactured in multiple locations, so the customer can actually designate where ABC Corp. should source the components. The final product is assembled...
In the context of the triple bottom line (TBL), which of the following is a performance...
In the context of the triple bottom line (TBL), which of the following is a performance measure of economic sustainability? Select one: a. Fines for environmental violations b. Corporate ethics and governance c. Revenue from new goods and services d. Measures of perceived value
ABC Inc. ABC Inc. (“ABC” or “the Company”), an SEC registrant, is a retailer that sells...
ABC Inc. ABC Inc. (“ABC” or “the Company”), an SEC registrant, is a retailer that sells men’s and women’s clothing and accessories. As an incentive to its employees, the Company established a compensation incentive plan in which a total of 100,000 options were granted on January 1, 20X1. On that date (the grant date), ABC’s stock price was $15.00 per share. The significant terms of the incentive plan are as follows: The options have a $15.00 “strike” or exercise price...
An electronic product takes an average of 8 hours to move through an assembly line. If...
An electronic product takes an average of 8 hours to move through an assembly line. If the standard deviation of 0.7 hours, what is the probability that an item will take between 7.3 and 8.3 hours to move through the assembly line? Do not round until you get your your final answer. Answer= (Round your answer to 4 decimal places, and report a probability value between 0 and 1.)
Command Company produces two types of electronic products, Product A and Product B. Electronic gaming products...
Command Company produces two types of electronic products, Product A and Product B. Electronic gaming products are hot products now and either product A or product b could be sold to keep the manufacturing facility operating a full capacity. The constraint is direct labour hours and it is insufficient to meet the combined demand for both.   Both products are processed through the same production departments. The relevant information is as follows: Product A Product B Sales Price $ $250 $140...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT