Activation Process Summary

Improved Essays
Activation procedures first begin with the designation of personnel to authorize declaration of disaster and signaling of resumption of normal processing, which TAMUITDRP effectively states that the President, Vice President, and Chief Information Officer hold these responsibilities. A team is also pre-organized with specific responsibilities if a confirmation of threat is declared. Within a large organization, each team has a leader (and alternates) that are key university personnel that are IT specialists. Within smaller organizations, such as TAMU, IT staff must be assigned to multiple teams with specific assignments based on the knowledge, experience, and availability (Texas A&M University, 2012). Another key player of DRP team is the DRP …show more content…
Cost and funding was not discussed except briefly highlighted in the administrative responsibilities overview and the testing the DRP section (Texas A&M University, 14, 56). These mentions only state to make sure plan is “cost effective” yet the DRP fails to designate how to do so. The lack of discussion of cost may have something to do with the lack of strategic decisions based on the BIA. The lack of business impact analysis is troublesome being that the entire DRP rests on its evaluation of the system and its criticality. According to the NIST document, the BIA is the primary source for determining resiliency and contingency planning strategies (Swanson, Bowen, Phillips, Gallup, & Lynes, 2010). The results of the BIA determines the amount of impact of loss could have on the university, determines the backup type and frequency, the type of alternative facility needed, and the need for mirroring of data (Swanson, Bowen, Phillips, Gallup, & Lynes, 2010). To effectively mitigate IT risks a complete RA and/or BIA should be available that includes an awareness of the wide range of potential risks to critical business/university systems. To properly mitigate risk there should be an organized method that is created to implement effective risk …show more content…
Having a solid and complete BCP/DRP not only ensures that the university establishes and maintains clients’, customers’, and suppliers’ trust in the security of their intellectual property and private data but it also facilitates legal compliance and privacy obligations for a more stable business future. It is imperative to identify, protect, and maintain security of the universities online systems from everyday internal and external digital threats. To do this there must be proper and up-to-date policies, procedures, and codes of conduct in place to ensure corruption of systems does not occur. There was a lack of attention to possible human error that could cause disastrous effect to the university and its IT systems. Personnel must be efficiently trained and supported in these critical IT processes and risk strategies to ensure that they do not unknowingly contribute to intrusions of systems and if so, what actions should be taken in the occurrence of a security breach. Security threats or breaches are bound to occur at some point in the universities lifespan; this is when insurance becomes a crucial measure in the planning of IT risk and recovery procedures. This business insurance should be maintained and updated to ensure coverage of new and emerging threats to the business landscape.

Related Documents

  • Improved Essays

    The vulnerabilities identified in part 1 assignment was mitigated by recommending the right solutions. In part2, the network security analyst identified and proposed solutions for the right network devices to protect the accounting firm's network from intruders and external cyber threats. In this final assignment section, the network security analyst of the accounting firm will propose the application/end-user security recommendation to protect the company’s sensitive information. The analyst will also ensure that the proper procedure and policies are in place to take care of network security and employees should be trained and aware of those policies from possible threats including cyber-attacks.…

    • 730 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Cyber Ark Case

    • 725 Words
    • 3 Pages

    Cyber Ark is an enterprise application cyber security company based in Israel with offices worldwide. The United States headquarters is in Newton, MA. with regional sales offices in Ft. Lauderdale, Houston, Las Angles and Chicago. The company is well known in the IT Security Company with a quality product designed to secure data in the enterprise as well as the cloud.…

    • 725 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Ba501 Week 1 Assignment

    • 740 Words
    • 3 Pages

    II Abstract Security is a need that is increasing at a rapid rate especially with a large organization and constant changes seem to be the norm.…

    • 740 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    INFO 290: Final Exam

    • 1200 Words
    • 5 Pages

    INFO 290 – Final Exam Name (Print) Cristian David Ramirez-Loaiza Signature______________ Date:____________ Answer any FOUR questions 1. Explain in detail with examples as to why a business needs a disaster recovery plan and Business Continuity plan?…

    • 1200 Words
    • 5 Pages
    Improved Essays
  • Improved Essays

    Given the University’s many diverse systems and disparate departmental roles managing the various systems the overall information security plan was not update to date nor consistent. There were obvious holes in the security plan which allowed a hacker to infiltrate the main domain server. The hacker secured administration rights on the server and they managed to infect other systems attached to the network. Thankfully, a trail of clues were found by the administrators.…

    • 671 Words
    • 3 Pages
    Improved Essays
  • Superior Essays

    Identify strategies to control and monitor each event to mitigate risk and minimize exposure Identify at least two types of security events and baseline anomalies that might indicate suspicious activity. One type of a security event that might indicate supicious activity is an authentication failures found in audit logs. Audit logs contain a high volume of events so particular attention on which events that should be specifically tracked and managed require consideration. An audit log can identify patterns of activity that can signal a security a potential breach. Whether the attack was successfull or not the audit information should be stored in a central respository for future forensic refernce if ever needed.…

    • 1084 Words
    • 5 Pages
    Superior Essays
  • Improved Essays

    The aim of this paper is to outline the dynamics of Walters Security. Walters Security’s main objective is to ensure a high level of network and information security for reach client. Customer and client information, payment information, personal files, bank account details- all this information cannot be fully restored once it has been lost or breached by criminals. The goal of this firm is developing an interdisciplinary research platform to develop a framework and provide benefits to eliminate breach-related vulnerability of information.…

    • 762 Words
    • 4 Pages
    Improved Essays
  • Superior Essays

    In an era where some of the biggest damage is done by simple keystrokes, cyber security is an essential part of any organization, whether big or small. The purpose of this report was to gather information regarding The University of Texas Health Science Center at San Antonio (UTHSCSA). Through proper use of research, network scanning, and social engineering the team was able to obtain valuable information regarding the infrastructure, policy, intellectual properties and the security of the Health and Sciences center. The Team would be able to analyze all the findings and point out key the interfaces that may potentially be impacted as well as the key threats and vulnerabilities. These findings were to be given to executives at the Health and…

    • 1298 Words
    • 6 Pages
    Superior Essays
  • Decent Essays

    First, it is important to understand that through the application of some of the NIST security control mechanisms, the threat in the case can be substantially minimized. Some of the main approaches and methods that may be used towards minimizing the threat described include enhanced security awareness and training of the users of the system, access control into the system under consideration, frequent system maintenance and upgrades, occasional audits into the system, protection of the system from non-secured program codes, application of intrusion detection systems to detect any form of intrusions into the system and the protection of the system from spywares and spam. 14.5 The first and perhaps the most important value of the threat is that…

    • 252 Words
    • 2 Pages
    Decent Essays
  • Decent Essays

    Recently UCLA was involved in a data breech in which hackers gained access to parts of UCLA Health's computer network where 4.5 million patient's sensitive information were accessed. This incident is a huge concern as it questions the ability of hospitals, health insurers and medical providers to safeguard the electronic medical records and other sensitive data that are collected. This network contained names, dates of birth, Social Security numbers, health plan identification numbers and medical information such as patient diagnoses. This access could have begun in September 2014 with some of the information dating back to 1990. Prior to the attack UCLA has been taking steps and spening tens of millions of dollars to strengthen its computer…

    • 154 Words
    • 1 Pages
    Decent Essays
  • Brilliant Essays

    (2006, February). Special Publication 800-18 REV 1: Guide For Developing Security Plans For Information Technology Systems. Retrieved October 30, 2015 from http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf NIST - National Institute of Standards and Technology. (2012, September). Special Publication 800-30 REV 1: Guide for Conducting Risk Assessments.…

    • 1450 Words
    • 6 Pages
    Brilliant Essays
  • Great Essays

    1. Purpose After several security incidents Greiblock Credit Union (GCU) Board of Directors needs a sound policy to address the situation. The main objective of this document is to improve the security culture of the organization. The specifications of this policy will address dynamic vulnerability analysis, intrusion detection, and incident response.…

    • 1879 Words
    • 8 Pages
    Great Essays
  • Improved Essays

    Disaster Recovery

    • 797 Words
    • 4 Pages

    Case Study #2: Disaster Recovery / IT Service Continuity Name Institution Affiliation Case Study #2: Disaster Recovery / IT Service Continuity Overview. Disaster recovery also known as business contingency plan is the ability for a business to be able to deal with any occurring disaster (Snedaker, 2013). We need to know that incase of disasters such data breach it is normally impossible for the business processes to run smoothly.…

    • 797 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    The Office of Personal Management was established by Theodore Roosevelt is considered to be the father of the cutting edge merit-based administration. Merit is a term which means the value of quality of something or someone. Merit selection ensures that selection is based only on a person's ability to perform the work. Merit selection aims to choose the best person for the job, resulting in a quality workforce. OPM's history, which started with the Civil Service Act in 1883 and formally renamed to the Civil Service Commission.…

    • 1150 Words
    • 5 Pages
    Improved Essays
  • Decent Essays

    The Security and Confidentiality policy is an important policy not just for the business but for students too as anything that disobeys orders can risk the safety of student accounts that actually hold personal information and student resources such as the shared area, if this gets corrupted then the college will face losing valuable lesson plans that have taken a long while to plan. As a college is a busy place, there is an increase chance of an intruder coming in and hacking systems to expose private information (college network) that are held on the server systems or another way by using a student’s account to plant malware, viruses or other threats through open workstations. The Data Protection Act says that no data should be leaked to…

    • 403 Words
    • 2 Pages
    Decent Essays