0% found this document useful (0 votes)
9 views10 pages

France Inc. Data Breach Response Policy

The Data Breach Response Policy for France Incorporated outlines procedures for preventing, identifying, and responding to data breaches affecting the company's technological infrastructure. It emphasizes the importance of training employees and implementing strict access controls to safeguard sensitive information. The policy aims to ensure that all personnel are informed and equipped to handle potential breaches effectively, thereby protecting the company's reputation and data integrity.

Uploaded by

jgrah2234
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views10 pages

France Inc. Data Breach Response Policy

The Data Breach Response Policy for France Incorporated outlines procedures for preventing, identifying, and responding to data breaches affecting the company's technological infrastructure. It emphasizes the importance of training employees and implementing strict access controls to safeguard sensitive information. The policy aims to ensure that all personnel are informed and equipped to handle potential breaches effectively, thereby protecting the company's reputation and data integrity.

Uploaded by

jgrah2234
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Running head: DATA BREACH RESPONSE POLICY 1

Data Breach Response Policy for France Incorporated.

Student Name

Liberty University

Studies in Information Security, CSIS 340

June 11, 2018


DATA BREACH RESPONSE POLICY 2

Data Breach Response Policy for France Incorporated.

Overview

The data breach response policy considers all the technological structure set up and run

by France Incorporated including computer systems, networks, clouds that are used to save,

send, and receive data from and by the company. It also considers affiliates, vendors that use the

network and third-party companies that supply technological services to France Incorporated.

With data breaches becoming a trend, companies must assure that regulations are in place to

prepare for such eventuality. The problem lies in the frequency that it keeps happening with

technological advancement. According to Telang (2015), since 2005, the United States

documented more than 4,400 data breaches affecting about one billion records. The gravity of

the impacts has pushed the company to study the area affected and the proper protocol in place

that must be implemented for a swift and successful control, and containment.

A team of professionals composed of IT and IS employees will provide proper instruction

and information to employees. They will also create a guideline to prevent former employees

from accessing company data. The second part of this guideline will include directives for

current employees to prevent unauthorized access and educate them on the ways to minimize

unwanted intrusion. Lastly, a protocol will also apply to third parties, vendors, and affiliate that

access our network at any point during their visit.

Purpose

The primary purpose of the policy is prevention; however, it is aimed to regulate

procedures on how to communicate, evaluated and assess data breaches and the proper protocol

to follow until resolution. From the moment the breach is suspected or confirmed either from

unauthorized access or utilization, the policy will elaborate on the different action and strategy to
DATA BREACH RESPONSE POLICY 3

be applied depending on the intensity and importance of the breach. The policy will also

confirm the conditions, enumerate the different category of a breach, proper applicable protocols,

and the duty of all who are concerned.

The policy will also assure that all personnel is informed enough to be part of the

prevention and help identify a problem. As stated by Flowerday and Tuyikeze (2016), this

protocol can also help distinguish employee behaviors from authorized to unauthorized and

sanction them accordingly. They reaffirm that the purpose of the ISO/IEC 27002 (2013) which

encompasses the data breach response policy is to equip, maintain, and orientate business

management with business requirements and regulations when faced with information security.

General Objective

France Incorporated understand the importance of all collected and saved data.

Management also sees the risk having this data accessed by employees, affiliates, or outsourcers.

Thus, why it is mandatory for all department to firstly abide by the rules which will clearly state

where to report potential threats, breach and how to rapidly address the situation. Moreover,

with the help of IT and IS department, regular and consistent monitoring will take place.

Protocol

Any IT, IS personnel, or any other employees that encounter situations where theft of

data, unauthorized access, download, disclosure, or usage of company data is suspected, took

place or is planned, must promptly send an email to our dedicated Information Security

department at breachreport@[Link] explaining the situation, or they can contact us at

111-222-3333. Once the department receives the information, a complete investigation will take

place. Moreover, in the case of a breach, the department will deploy the appropriate rules and

procedures for fast resolution and send the report to management for proper actions or sanctions.
DATA BREACH RESPONSE POLICY 4

Scope

As stated above, the data breach response policy applies to all personnel, partners,

associates, and visitors who access, utilize, save, distribute the data of France Incorporated. The

range also covers personal and company devices. Anyone and any device that accesses our

network will automatically fall under the scrutiny of this policy and appropriate legal and safety

actions and sanctions from France Incorporated.

Policy Compliance

Initially, France Incorporated will set up a level of access guaranteeing that only

appropriate person can access specific data depending on their position, the need for the data and

their level of clearance and security. The IT and IS team will closely monitor every usage and

access. This rule will prevent unauthorized users from obtaining unapproved data and will also

help track the user, the time and the reason.

From the moment a breach is suspected, analyzed, or confirmed, our IT and IS team will

automatically deny access to the intruder, and the location of the unauthorized access and details

about the breached data will be activated. A team constituting of members from different

departments such as IT, IS, legal, Human Resources will evaluate the situation for proper actions

and apply the already elaborated damage control procedures.

Findings

Authors Kim, Johnson, and Park (2017) explained that for the most part that security or

data breaches involve loss information or illegal use of consumers credit card. However, for

businesses like France Incorporated which data constitute customer sensitives and private

information primarily, security and data breaches is as essential and as devastating to their brand

and image. As much as technology is widely used, convenient and revolutionizing the business
DATA BREACH RESPONSE POLICY 5

world, it also comes with challenges such as data breaches that can produce havoc and damage a

company's reputation.

The importance of this policy is better explained by authors Flowerday and Tuyikeze

(2016) who stated in their research that information security policy helps management

distinguish employee patters. From these patterns, further research can then help categorize

permitted actions and unauthorized actions; and from the accumulated data, companies can work

on sanctions according to the unwanted actions. They also pointed out that with the help of the

ISO/IEC 27002 (2013) management now has rules to aid in compliance with company policy to

better protect their data.

All company computers contain the latest version of anti-virus and frequent scans will

take place automatically to prevent intrusion. Access to social media website and other unrelated

work sites will also be blocked from employee computers’ and under no circumstances,

employees should refrain from using external drives or thumb drives; they must also refrain from

bringing personal computer or access company's network on such devices.

The IT and IS department must encrypt all data saved on company devices or the cloud.

Clear separation of regular data from sensitive data is needed so the latter can be securely filtered

and properly handled. As previously stated, the IT and IS team will select a team of four trained

technicians to train, guide, and assist employees, so they know how to handle sensitive data

better.

Related Standards

The Team

The primary concern about the data breach response policy is that the proper team is

already available for fast response and resolution. It is counterproductive to have a policy in
DATA BREACH RESPONSE POLICY 6

place and not the trained personnel. As the technology evolves so are hacking and breaches

techniques. Even though is it costly to hire, train and provide continued training, France

Incorporated vowed to set proper budget in place, and with the help of the Information Security

director, a plan will be elaborated to provide initial and continued training.

Internal Training

A trained information security team cannot hold the weight of control without the support

of regular employees. Thus why, France Incorporated will also make sure that a representant of

the Information System team holds a meeting twice a month to go over regulations, possible

problems that can arise from negligent or careless behavior and a detail presentation about our

policies, implementations, sanctions to minimize the chance of a breach. Visitors, vendors, and

affiliates will also be under restrictions and sanctions.

As stated by authors Such, Gouglidis, Knowles, Misra, and Rashid (2016), precise

information about internal policies should be available and presented in a simplified way for

faster assimilation by employees. The representant from the IS and IT department must

methodically explain the fundamental concepts and reasoning in a way to encourage

participation and not forced adherence. Uniform and logical steps and protocols are to be in place

to prevent confusion and non-adhesion.

Definitions

Data Breach: Situation where sensitive and private data have been accessed, modified, or deleted

without prior authorization.

Unauthorized Access: The viewing of private, confidential, and sensitive data without

permission.
DATA BREACH RESPONSE POLICY 7

Safeguard: structure in place by the company with conjuncture of the IS and IT department to

secure and identify, prevent, decrease data breach.

Encryption: coding of a data to prevent readability without decoding key.

Sensitive data: Data in the hands of the wrong group that can cause harm to an individual, a

group, or company.

Terms

Sohrabi Safa, Von Solms, and Furnell (2016) reminds us that the Internet is a vast

network; therefore, the risk of breaches is imminent. Hackers and unauthorized users employ

different techniques as the technology evolves and these techniques exploit confidentiality,

integrity, and availability of information. Moreover, for that, users and companies must first be

always aware of the constant change, danger, and risks. That is why the first step for France

incorporated is to bring awareness to its employees and affiliates regarding the risks, the rules,

and the proper steps. Secondly, the company will have its IT and IS team receive frequent

training to keep up with the changes. The Information Security with the help of the legal

department will go over the clear distinction of user privilege, and level of access and what

information can be accessed and under which conditions. They will jointly come up with the

guideline that indicates how to dispose and encrypt data properly, report a potential or actual

breach, where to submit the breach report, and the team that will be assigned the case. Upon

investigation results, the team will relay the information to the legal and human resource

department for sanctions, disciplinary process, and legal damage control.

Summary

No matter the company, regulations, and protocols are valuable because they set the

difference between a company that is ready and one that wishes they do not have to deal with a
DATA BREACH RESPONSE POLICY 8

data breach. Misinformation about the data breach being about consumer credit card is common

and as briefly mentioned earlier. However, it is clear that sensitive information is a broader

concept that goes from employees’ information to clients’ information. As long as the

information contains data that can be valuable to someone else or can cause harm to the owner if

placed in the wrong hand, it is worth protecting. It is not enough for companies to have

procedures or rules and not implement them. Furthermore, regulations will not suffice if they do

not have a trained and knowledgeable team that is aware of the danger and risk and are always

involved in keeping with new trends. It is in the best interest of a company to invest in security

protocol, training, and continued training. Technology will not stop evolving, as convenient as it

is, one misstep can jeopardize a company’s future; besides, it is more costly to fix a reputation

than to invest in prevention.


DATA BREACH RESPONSE POLICY 9

References

Data Breach Response policy. (n.d.). Retrieve from

[Link]

Flowerday, S. V., & Tuyikeze, T. (2016). Information security policy development and

implementation: The what, how and who. Computers & Security, 61, 169-183.

doi:10.1016/[Link].2016.06.002

Johnston, A. C., Warkentin, M., McBride, M., & Carter, L. (2016). Dispositional and situational

factors: Influences on information security policy violations. European Journal of

Information Systems, 25(3), 231-251. doi:10.1057/ejis.2015.15

Kim, B., Johnson, K., & Park, S. (2017). Lessons from the five data breaches: Analyzing framed

crisis response strategies and crisis severity. Cogent Business & Management, 4(1)

doi:10.1080/23311975.2017.1354525

Moody, G. D., Siponen, M., & Pahnila, S. (2018). Toward a unified model of information

security policy compliance. MIS Quarterly, 42(1), 285.

Siponen, M., Adam Mahmood, M., & Pahnila, S. (2014). Employees’ adherence to information

security policies: An exploratory field study. Information & Management, 51(2), 217-

224. doi:10.1016/[Link].2013.08.006

Sohrabi Safa, N., Von Solms, R., & Furnell, S. (2016). Information security policy compliance

model in organizations. Computers & Security, 56, 70-82.

doi:10.1016/[Link].2015.10.006

Such, J. M., Gouglidis, A., Knowles, W., Misra, G., & Rashid, A. (2016). Information assurance

techniques: Perceived cost effectiveness. Computers & Security, 60, 117-133.

doi:10.1016/[Link].2016.03.009
DATA BREACH RESPONSE POLICY 10

Telang, R. (2015). Policy framework for data breaches. IEEE Security & Privacy, 13(1), 77-79.

doi:10.1109/MSP.2015.12

Common questions

Powered by AI

The ISO/IEC 27002 (2013) provides a framework for information security management, including protocols for data breach response. For France Incorporated, it structures their data security measures, ensuring compliance with established best practices for protecting sensitive information. The standard aids in distinguishing authorized from unauthorized employee behaviors and adopting sanctions accordingly, improving overall data integrity and security within the company .

France Incorporated employs strategies such as data encryption, separation of data based on sensitivity, and restricting access to sensitive information to select employees. They reinforce this with an anti-virus system, block non-work-related websites, restrict use of external drives, and provide comprehensive employee training to manage sensitive data securely and mitigate unauthorized access risks .

Policy development, backed by monitoring employee behaviors, helps France Incorporated identify actions that stray from authorized use. By understanding typical user patterns through monitoring, breaches or irregularities can be rapidly identified, allowing for quicker responses and the capability to enforce sanctions. This differentiation ensures all actions align with business regulations, maintaining data integrity and security .

Consistent monitoring is crucial because it helps in the early detection of potential threats, ensuring prompt response to any breaches at France Incorporated. It includes tracking data access and usage patterns, which identify deviations that could indicate unauthorized access, thus enabling quick intervention to prevent or mitigate data breaches .

Internal training plays a vital role in minimizing data breaches at France Incorporated by educating employees on recognizing potential threats and adhering to security protocols. Employee involvement is crucial because security measures are only effective if personnel understand and implement them correctly. Regular training sessions help reinforce knowledge, and encourage reporting of suspicious activities, thus being an integral part of the overall security strategy .

France Incorporated employs access control measures by granting data access based on position, need, and security clearance. If a breach is suspected or confirmed, the IT and IS team denies further access to the intruder, assesses the breach, and initiates damage control procedures. This involves activating protocols to block access from unauthorized users and conducting a thorough investigation to track breach details .

A data breach can severely damage a company's reputation, affecting customer trust and financial stability. France Incorporated understands this and prioritizes prevention and rapid response to protect its brand image. By embedding robust security measures, continuous training, and strict compliance protocols, they aim to minimize the occurrence and impact of breaches, thus safeguarding their reputation and maintaining stakeholder confidence .

A robust data breach response policy comprises several components, including prevention strategies, access controls, response protocols, and continuous training. For France Incorporated, the policy involves securing the technological infrastructure, educating employees, and involving IT and IS teams in monitoring and responding to breaches. Access controls restrict data per user roles, and continuous training ensures all personnel are aware of threats and prevention strategies, which is critical as technology and threats evolve .

Third-party vendors add complexity to data breach policies as they increase potential access points for breaches. France Incorporated mitigates these risks by applying the policy to all affiliates and vendors that access their network, ensuring they adhere to the same stringent protocols as internal staff. This includes monitoring all network usage and requiring compliance with data handling and access restrictions .

Investing in prevention and continuous training is more beneficial as it significantly reduces the risk of breaches, thus avoiding the costly and damaging aftermath of data breaches. For France Incorporated, prevention strategies and continuous updates to security knowledge preserve reputation and financial stability more effectively than reactionary measures after an incident occurs, where damage control could be more expensive and resource-intensive .

You might also like