170 likes | 296 Views
2012 CWAG Annual Meeting. State Agency Data Breaches Loss prevention, response and remediation strategies. Identity Exploitations: 12+ years of our cases. Employees. Mortgagees. Job Seekers. Insured. The Scams Persist and This is Now an Industry. + Prevention + Detection
E N D
2012 CWAG Annual Meeting State Agency Data Breaches Loss prevention, response and remediation strategies
Identity Exploitations: 12+ years of our cases Employees Mortgagees Job Seekers Insured The Scams Persist and This is Now an Industry
+ Prevention + Detection + Analysis & Response
Data Loss Prevention: Comprehensive Approach People, Processes and Systems to Identify, Monitor and Protect Data... • + In Use (endpoints, devices) • + In Motion (network) • + At Rest (storage)
Data Loss Prevention: Conduct Gap Analysis + Your Current Security System Versus What You Need to Have in Place + What Other Data Do You Hold That Could Become Valuable? + What Processes (Internal and/or External) Can be Tightened Up? + What Other Service Providers or Counter-Party are Points of Vulnerability?
Analysis Data Theft Is Preceded by Smaller Intrusions...Catch Me if You Can + We Can Home In On Who Is Attacking + We Can Identify How Much Data Went Out + What Data Went Out, Where It Went + Stop the Bleeding
State Agency State Agency Supplier
Analysis An Incident Response Function and Plan Must be In Place + Discover Attack and Exfiltration + Identify Data Which Has Gone Out and Where It Went + Contain Damage + Eradicate Perpetrator’s Presence + Recover System and Data Protection in Secure Manner + Conduct in Forensically Sound Manner + Identify What Led to Intrusion to Prevent
Monitoring, Detection and Remediation Providers: www.idanalytics.com www.inguardians.com www.mandiant.com www.mantech.com www.krollfraudsolutions.com www.intersections.com
Self-help resource + 20 Security Controls For Effective Cyber Defense - The SANS Institute http://www.sans.org/critical-security-controls/ + Consortium-led Approach to Determining Best Practices and Most Cost Effective Security Across Government Bodies
Wireless Access Code: 9166703926