Don't get bogged down...
Published: 19 September 2007 15:27 GMT
Any organisation trying to cope with the consequences of a data breach should beware of get bogged down in the details, according to a former US Air Force major.
The US Air Force experienced a data breach in May 2005 when 33,000 personal staff records were downloaded from a management system.
Bruce Jenkins, a recently retired major from the US Air Force and now security director at Fortify Software, was on the team responsible for managing the fallout from the data breach.
silicon.com's Full Disclosure campaign - what we are asking for...
silicon.com wants the government to review its data protection legislation and improve the reporting of information security breaches in the public and private sectors.
We are calling for greater public debate and for the government to consider legislation that would require organisations that suffer information security breaches to alert their customers if there is a chance the breach has put individuals' sensitive personal data at risk.
We want to hear your views about this campaign and the issues it raises. Make your voice heard by leaving a Reader Comment below, emailing us at editorial@silicon.com or signing the 10 Downing Street e-petition.
When the breach occurred, a crisis action team was activated - consisting of programme management offices, security analysts and special investigators to liaise with the Air Force's network operators and security centre.
The team then did a top-to-bottom review of all the applications within the breached management system which included reviewing the system's password procedures, log on methods and revalidating privileges.
The new identity authentication and system design policies were in place within 90 days of the breach.
Speaking at the Gartner IT Security Summit, Jenkins said it is important to "take baby steps but to do something" when managing a breach and not get caught up in the exact details of an action - but to make sure lessons are learnt and any early successes are communicated to the rest of the workforce.
Jenkins added it is also important to quantify the cost of the data breach when implementing the subsequent security programme.
He added those managing the response to a data breach should sell hard to key leaders to get the job done but "not shove things down the throats of the developers" - and instead highlight the improvements any changes will make to their work.
Back to Full Disclosure Special Report
Super comms database ditched for next year?
Bye-bye big brother
'No lost memory sticks' shocker for gov't dept
It had to happen sooner or later
CEOs told - take responsibility for 'toxic' data
Information Commissioner: "it's time for the penny to drop"
Data breach at Virgin prompts encryption order
3,000 details lost on CD…
Lost data total nears 30 million records
Missing laptops, USB sticks and CDs take their toll
Stories from around the web...
London revealed as hot spot for online credit card fraud News.com
Researchers: Cyberattacks outstripping defences ZDNet.co.uk
Honesty the best online policy bbc.co.uk
Why small online fraudsters get away with it The Guardian
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page