The network security incident response team reports to you


Network Security Breach- Stop or collect evidence? WORD COUNT 350
The Network Security Incident Response Team reports to you the Chief Information Security Officer (CISO). In real time there is an alert which indicates that a large, encrypted file is being downloaded to an external system by an unauthorized internal user. The internal user does not know the contents of the data because (its encrypted), but you (CISO) knows the user has access to very sensitive information. You have to decide immediately whether to stop the download in process, or continue to monitor and collect further evidence. What are the things you should consider in making this decision, and based on your choice, what would be your follow-up actions? [Obviously the answer can be taken in the context of a specific enterprise network (publicly known security breaches), and with knowledge of the kind of information the internal user has access to. You may respond either in general, in terms of a specific real world situation, or in terms of a fictitious situation, such as if it happened where you work.]

Request for Solution File

Ask an Expert for Answer!!
Computer Network Security: The network security incident response team reports to you
Reference No:- TGS0130910

Expected delivery within 24 Hours