Computer security incident response team

Assignment Help Basic Computer Science
Reference no: EM132716148

Scenario

After the recent security breach, Always Fresh decided to form a computer security incident response team (CSIRT).

As a security administrator, you have been assigned the responsibility of developing a CSIRT policy that addresses incident evidence collection and handling. The goal is to ensure all evidence collected during investigations is valid and admissible in court.

Consider the following questions for collecting and handling evidence:

1. What are the main concerns when collecting evidence?

2. What precautions are necessary to preserve evidence state?

3. How do you ensure evidence remains in its initial state?

4. What information and procedures are necessary to ensure evidence is admissible in court?

Tasks

Create a policy that ensures all evidence is collected and handled in a secure and efficient manner. Remember, you are writing a policy, not procedures. Focus on the high-level tasks, not the individual steps.

Address the following in your policy:

- Description of information required for items of evidence

- Documentation required in addition to item details (personnel, description of circumstances, and so on)

- Description of measures required to preserve initial evidence integrity

- Description of measures required to preserve ongoing evidence integrity

- Controls necessary to maintain evidence integrity in storage

- Documentation required to demonstrate evidence integrity

Reference no: EM132716148

Questions Cloud

What is the weighted average cost of capital : The share market has expected return of 8% and the risk - free rate is 3%. What is the weighted average cost of capital for Lasco farms
Discuss the overall process of developing new software : Discuss the overall process of developing new software. Please also note the differences between software development and methods.
Explain the features of just-in-time manufacturing system : In order to answer these questions Esther prepares a cost analysis every time she plans an audit trip. Explain the features of just-in-time manufacturing system
What would different cost between theirs two product line : What would the different cost between theirs two product line, how would this may be more profitable than the other
Computer security incident response team : After the recent security breach, Always Fresh decided to form a computer security incident response team (CSIRT).
Make the variable-costing income statement for same period : Selling & administrative expenses include $1.50 of variable cost per unit sold. Make the variable-costing income statement for the same period
Compliance-sarbanes-oxley act : Evaluate the five essential control components for managers and auditors established by the Committee of Sponsoring Organizations of the Treadway Commission
What is the maximum amount Perfume Division pay : Assume the Bottle Division has no excess capacity and can sell everything produced externally. What is the maximum amount Perfume Division would willing to pay
Scotiabank-kabbage partnership : What are the success factors in the Scotiabank-Kabbage partnership? Under what circumstances should Scotiabank seek fintech partnerships?

Reviews

Write a Review

Basic Computer Science Questions & Answers

  What is stand-alone-corporate and market risk

What is stand-alone, corporate, and market risk? What is the relevance of risk measures in the financial decision-making process?

  Maturity stages and performance dimensions

Define each of the maturity stages and performance dimensions. What are the key concepts from each section?

  Prohibition movement with modern war

Compare and contrast the Prohibition movement with the Modern War on Drugs-and specifically with the battle over the legalization of marijuana.

  How does six sigma relate to it project

What is Six Sigma? How does Six Sigma relate to IT Project? What type of data does Six Sigma collect?

  What is the purpose or significance of unit testing

what is the purpose or significance of unit testing?

  Developing and implementing risk management framework

What are the main challenges in developing and implementing a risk management framework for Blue Wood? How does the ownership structure affect these challenges?

  Mostly focusing on mobile networks

In this discussion we're looking at wireless networks, mostly focusing on mobile networks.

  Two measures of process capability are cp and cpk

Two measures of process capability are Cp and Cpk. For a given process, the two measures (choose only one response below and complete the sentence):

  How can users help analysts create better erds?

How can users help analysts create better ERDs?

  Develop a boolean expression for the truth table

Develop a Boolean expression for the truth table shown below. Express the answer in both the complete and simplified SOP formats. Use an apostrophe to indicate the use A' for A

  Implement the data structure priorityqueue

Implement the data structure PriorityQueue, which offers quick execution of the following operations: adding an element, extracting the smallest element.

  Microsoft operating systems-standard life cycle model

Microsoft, after 14 years, ended support of Windows XP. Shortly after Microsoft introduced Windows 10. It falls right into a very standard Life Cycle mode

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd