ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Companies advised on data-breach clean-up

Gemma Simpson silicon.com

Published: 20 Sep 2007 14:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Any organisation trying to cope with the consequences of a data breach should beware of getting bogged down in the details, according to a former US Air Force major.

The US Air Force experienced a data breach in May 2005 when 33,000 personal staff records were downloaded from a management system.

Bruce Jenkins, a recently retired major from the US Air Force and now security director at Fortify Software, was on the team responsible for managing the fallout from the data breach.

When the breach occurred, a crisis action team was activated — consisting of programme-management officers, security analysts and special investigators to liaise with the Air Force's network operators and security centre.

The team then did a top-to-bottom review of all the applications within the breached management system, which included reviewing the system's password procedures, log-on methods and revalidating privileges.

The new identity-authentication and system-design policies were in place within 90 days of the breach.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Speaking at the Gartner IT Security Summit, Jenkins said it is important to "take baby steps but to do something" when managing a breach and not get caught up in the exact details of an action. Jenkins said, however, that it is also important to make sure lessons are learnt and any early successes are communicated to the rest of the workforce.

Jenkins added it is also important to quantify the cost of the data breach when implementing the subsequent security programme.

He added that those managing the response to a data breach should sell hard to key leaders to get the job done but "not shove things down the throats of the developers", instead highlighting the improvements any changes will make to their work.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
2 out of 2 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Project Manager for Care Records System (CRS) - 400-500pd

Take necessary action to maintain control of the projects, alerting the Programme Manager to circumstances that put the projects at risk of failure. ...

Test Lead Thames Valley

Huxley Associates client requires a Test Lead with experience of working at the programme level, for a hands-on role (e.g.undertaking creation of ...

Application Support Team Lead - Support Analyst - East Midlands

To be considered, you will need to demonstrate the following: - A degree or achieved proficiency in SFIA skills at level 4 (Details of SFIA available ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments