Question

In: Computer Science

Consolidated Electronics Group, Inc. is a manufacturer and supplier of avionics equipment to various airlines across...

Consolidated Electronics Group, Inc. is a manufacturer and supplier of avionics equipment to various airlines across the continental United States. Recently, the company has laid off several employees, which left many in the company in a disgruntled state. Now, the information technology (IT) staff has reported to management a significant spike in network attacks numbering in the thousands. Reports from the intrusion detection system (IDS) indicate that two of these potential attacks may have compromised highly classified plans for a new prototype avionics switchboard, which is expected to revolutionize the market. The IT staff suspects that the attacks and potential security breach may have something to do with the recently laid off staff. Assignment Instructions: The U.S. National Institute of Standards and Technology (NIST) is a recognized authority for providing security standards, guidelines and procedures. NIST provides a large array of other security related documents, which are of great value to information security professionals.

For this assignment, you are asked to use NIST SP 800-61 Rev. 2

http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

While this document is quite large, you will find Section 3 starting on page 21 helpful for this assignment. Using the guidance from this NIST document, craft an incident response plan that includes:

A description of the specific measures that would be taken to investigate a security breach.

An explanation of steps taken to prevent future attacks and to secure the company’s information systems

A communication plan to disseminate the results and findings of this event to the organization

Your plan should be two to three pages.

Solutions

Expert Solution

Measures taken to investigate the security breach:

1. Check for physical loss of assets like hard drives, printed materials, CD/DVDs.

2. Flaws in the access control facilities and gather details on how the attack was performed.

3. Contact information and background check of laid-off employees.

4. Ports and other hardware are used for the security breach.

5. A detailed analysis of IDS reports, audit trails, log monitoring etc.

6. Monitor the whole network for undiscovered vulnerabilites which may exists.

To prevent future security breaches, specific measures to be taken are:

1. Identify loopholes in security and close them.

2. Secure assets like CDs, DVDs, hard disks,etc.

3. Minimize online access to critical hardware like database servers that are not necessary.

4. Use stronger encryption and authorization techniques for access to critical data.

5. Use of proper malware detection and antivirus software’s across all systems.

6. Use access to critical data on business need to know basis. Two-step authentication and verification mechanism should be used.

The communication plan should be:

1. The steering committee - CIO, CISO, CFO and other heads of departments should be briefed in person about the incident.

2. Employee awareness programs should be conducted to make employees aware of basics of security and how to protect them against security attacks.

3. Immediately the security operation center should be contacted and the backup plan and procedures to be performed in such scenarios should be carried out.


Related Solutions

Consolidated Electronics Group, Inc. is a manufacturer and supplier of avionics equipment to various airlines across the continental United States.
Consolidated Electronics Group, Inc. is a manufacturer and supplier of avionics equipment to various airlines across the continental United States. Recently, the company has laid off several employees, which left many in the company in a disgruntled state. Now, the information technology (IT) staff has reported to management a significant spike in network attacks numbering in the thousands. Reports from the intrusion detection system (IDS) indicate that two of these potential attacks may have compromised highly classified plans for a...
Electronics Inc. buys and sells photocopy equipment that are used in businesses across Ontario. The company...
Electronics Inc. buys and sells photocopy equipment that are used in businesses across Ontario. The company follow IFRS. Unit selling prices range from $10,000 to $100,000. Electronic Inc. sells a photocopy system to Centennial College on September 10th, 2020. The selling price for the photocopy equipment is usually $85,500. - Electronic Inc. will also install the photocopy system. The estimated fair value of installing the photocopy system is $2,700. Electronic Inc. will also provide one year of maintenance service for...
Electronics Inc. buys and sells photocopy equipment that are used in businesses across Ontario. The company...
Electronics Inc. buys and sells photocopy equipment that are used in businesses across Ontario. The company follow IFRS. Unit selling prices range from $10,000 to $100,000. Electronic Inc. sells a photocopy system to Centennial College on September 10th, 2020. The selling price for the photocopy equipment is usually $85,500. - Electronic Inc. will also install the photocopy system. The estimated fair value of installing the photocopy system is $2,700. Electronic Inc. will also provide one year of maintenance service for...
Compact Electronics is a leading manufacturer of digital camera equipment
Compact Electronics is a leading manufacturer of digital camera equipment. Assume the following transactions occur during the year ended December 31, 2021.   Required: Record any amounts as a result of each of these contingencies. 1. Accounts receivable were $29 million (all credit) at the end of 2021. Although no specific customer accounts have been shown to be uncollectible, the company estimates that 3% of accounts receivable will eventually prove uncollectible. 2. Compact Electronics is the plaintiff in a $5...
The gym is looking for a new equipment supplier. The candidate manufacturer provided for the equivalence...
The gym is looking for a new equipment supplier. The candidate manufacturer provided for the equivalence testing a set of ten dumbbells with a nominal weight of 12-kg. The sample mean and sample standard deviation of the weight of these sample dumbbells are 12.06-kg and 0.06-kg, respectively. The gym is going to sign a contract if the mean weight of a dumbbell is within 0.05-kg of the nominal weight. Would you recommend the gym to sign a contract with this...
Winger Airlines Co. has been sued by Schock Electronics, Inc. for $50,000. Attorneys for Schock Electronics,...
Winger Airlines Co. has been sued by Schock Electronics, Inc. for $50,000. Attorneys for Schock Electronics, Inc. are confident that Schock will win the case and will be awarded the full amount. Attorneys for Winger Airlines Co. agree that Winger will probably lose the case and be required to pay the full amount. a. What is the correct treatment of this loss contingency for Winger Airlines Co.’s financial statements? Show any related journal entry. b. How should Schock Electronics, Inc....
Q4. A manufacturer of electronics products is considering entering the telephone equipment business. It estimates that...
Q4. A manufacturer of electronics products is considering entering the telephone equipment business. It estimates that if it were to begin making wireless telephones, its short run cost function would be as follows: Q (thousands) AVC                 AC                   MC 9                                  41.10               52.21               30.70 10                                40.0                 50.0                 30.10 11                                39.1                 48.19               30.10 12                                38.40               46.73               30.70 13                                37.90               45.59               31.90 14                                37.60               44.74               33.70 15                                37.50               44.17               36.10 16                                37.60               43.85               39.10 17                                37.90               43.85               39.10 18                                38.40               43.96               46.90 19                                39.10              ...
You are the manufacturer of various pollution abatement equipment and want to maximize your sales of...
You are the manufacturer of various pollution abatement equipment and want to maximize your sales of this equipment year after year. Your industry does not create pollution. What ONE policy would you most like to see imposed on polluters? Explain why.
Lindsay​ Electronics, a small manufacturer of electronicresearch​ equipment, has approximately 7 comma 100 items in...
Lindsay Electronics, a small manufacturer of electronic research equipment, has approximately 7 comma 100 items in its inventory and has hired Joan Blasco-Paul to manage its inventory. Joan has determined that 8% of the items in inventory are A items, 32% are B items, and 60% are C items. She would like to set up a system in which all A items are counted monthly (every 18 working days), all B items are counted quarterly (every 59 working days), and...
TopNotch Medical, Inc. is a supplier of medical equipment. It recently introduced a new line of...
TopNotch Medical, Inc. is a supplier of medical equipment. It recently introduced a new line of equipment that may revolutionize the medical profession. Because of the new technology, potential users of the equipment are reluctant to purchase the equipment, but they are willing to enter into a lease arrangement if they can classify the lease as an operating lease. The new equipment will replace equipment that TopNotch has been selling in the past. Leasing the new equipment will result in...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT