Ashley Madison Case Study

723 Words2 Pages

Not only Ashley Madison, but most of the high profile companies reported data breach in recent years. For instance, in March, health care insurance provider Premera Blue Cross reported the hack which had compromised 11 million customer details including financial information such as bank account. Even in the case of Ashley Madison the motivation was different but eventually data, credit card information was compromised. After reviewing the case of Ashley Madison, Here are some of the recommendations gathered from online and text book.
Developing Security program: Security program describes plan, policies, individuals and initiatives related to security. The one and only one mission of security program is to contain the risks to the information asset of the organization. Now this depends on the culture, size, and security personnel budget. Considering Ashley Madison size and most of its operations is performed online, it should have rigorous training platform for both technical and non-techincal staff. Programs offered by professional agencies such as SANS, ISSA and CSI provides or subsidizes these resources. …show more content…

Following compliance guide line provided by NIST SP 800-16 that describes security and training requirements is another way to boost the awareness of the employees. These kind of training and follow of compliance emphasize on roles rather than fixed content providing flexibility, adaptability, and longevity. Furthermore varying method of training with respect to different users is also beneficial. For example training for general users, training for managerial users and training for technical users which can be categorized by job category or job functions. According to the text book Management of Information Security by Whitman and Mattord- there are seven steps methodology to implement

Open Document