Companies advised on data-breach clean-up

By Gemma Simpson, Special to ZDNet Asia
Friday, September 21, 2007 11:26 AM

Any organization trying to cope with the consequences of a data breach should beware of getting bogged down in the details, according to a former U.S. Air Force major.

The United States Air Force experienced a data breach in May 2005 when 33,000 personal staff records were downloaded from a management system.

Bruce Jenkins, a recently retired major from the United States Air Force and now security director at Fortify Software, was on the team responsible for managing the fallout from the data breach.

When the breach occurred, a crisis action team was activated--consisting of program-management officers, security analysts and special investigators to liaise with the Air Force's network operators and security center.

The team then did a top-to-bottom review of all the applications within the breached management system, which included reviewing the system's password procedures, log-on methods and revalidating privileges.

The new identity-authentication and system-design policies were in place within 90 days of the breach.

Speaking at the Gartner IT Security Summit, Jenkins said it is important to "take baby steps but to do something" when managing a breach and not get caught up in the exact details of an action. Jenkins said, however, that it is also important to make sure lessons are learnt and any early successes are communicated to the rest of the workforce.

Jenkins added it is also important to quantify the cost of the data breach when implementing the subsequent security program.

He added that those managing the response to a data breach should sell hard to key leaders to get the job done but "not shove things down the throats of the developers", instead highlighting the improvements any changes will make to their work.

Gemma Simpson, of Silicon.com reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

How to protect yourself from RAID-related UREs

Enterprise Servers & Storage

An Unrecoverable Read Error during a RAID rebuild can ruin an entire day. Scott Lowe talks about UREs and how you can avoid falling victim to this silent threat.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web