Computer Security
Computer Security
A case study analysis of a security breach at Commerce Bank and the steps they took to assess and manage the problem.
4,107 words (
approx. 16.4 pages) |
10 sources |
APA | 2008
Paper Summary:
This paper discusses computer security and its importance for organizations. The paper presents an information security strategic plan or "defense plan" as an overview of what needs to be done for any organization dependent on information technology as a business driver. The paper presents a case study of Commerce Bank and how they handled a breach in security.
Table of Contents:
The Hacking that was Thwarted
Managing the Risk
Defending the Network and the System
Information Security Policies
Assessment of Publicly Accessible Resources and Network Probing
Iinternal Security Assessment
Tools for Ongoing Defense
Third-party Audit and Assessment
Physical Security Assessment
Security Logs Analysis
Information Security Training and Awareness
IT Governance as Part of Executive Managment Responsibilities
Conclusion
From the Paper:
"Commerce Bank is indeed lucky because as a result of good corporate governance and an information security methodology in place, no great harm was done. By immediately informing customers of what went on, the level of awareness was promoted thereby any attempt by the hackers to use the data for other nefarious activities will not be fruitful because those are already flagged by the law enforcement agencies especially the FBI. Information security was proven in this case to be a matter not only for the affected organization but community and society as well. From beginning to the end, clear lines of reporting and controls were defined that mitigated the risk at its onset. The information security strategic plan or simply "defense plan" presented in this paper is an overview of what needs to be done not only for the bank but any organization dependent on information technology as a business driver."
Sample of Sources Used:
- Bowen, Pauline, Hash, Joan & Wilson, Mark. (2006, Oct.) NIST Special Publication 800-100 - Information Security Handbook: A guide for managers. [Online] Retrieved Oct. 31, 2007 from the NIST database on the Website: http://csrc.nist.gov/publications/nistpubs/800-100/SP800-100-Mar07-2007.pdf
- Dumitru, Alexandru. (2007, Oct. 11). Hacker attacks bank, gets pummeled - Here's a good example of cyber-security! [Online] Retrieved Nov. 4, 2007 from the Softpedia database on the Website: http://news.softpedia.com/news/Hacker-Attacks-Bank-Gets-Pummeled-68219.shtml.
- Howard, Jeanne & Hyland, Molly. (2007, Oct. 9). A statement from Commerce Bank. [Online] Retrieved Nov. 4, 2007 from the Commerce Bank database on the Website: http://www.commercebank.com/about/news/nr100907statement.asp.
- ISACA. (2007). IS standards, guidelines and procedures for auditing and control professionals. Rolling Meadows, IL: ISACA.
- ISO/IEC. Information technology - security techniques - code of practice for information security management (ISO/IEC 17799:2005). Geneva, Switzerland: ISO Copyright Office, 2005.
Computer Security (2012, January 15). Retrieved February 12, 2012, from http://www.academon.com/Case-Study-Computer-Security/108781
"Computer Security" 15 January 2012. Web. 12 Feb. 2012. <http://www.academon.com/Case-Study-Computer-Security/108781>