Case Study On DOS Attack

2141 Words5 Pages

1. Analysis
The overall situation is that the company is being hit with a DOS attack. They are not prepared so it leaves everyone to run around panicking. The procedures are out of date so if the new night shift employee had looked at them he still would have been lost. The third party security company is not detecting this attack so they never stepped in. The biggest problem is that most of the executives are more concerned with PR than fixing the problem. Finally when the personnel from our company get to the third party security center they will not let her in because she is not on the list. Then when she finally gets in they try and stop the attack, but for every request rejected the hacker pops up 10 more to take its place. They are overwhelmed by the attacker and then he just stops the attack. The company is trying to figure out whether to shut down and clean the system or to just let it continue to run. The main argument …show more content…

Risk management is a key part because the company has to figure out how they want to minimize the risk of the attack. They completed a risk assessment when fighting off this DOS attack. The assessment started with classifying the attack, then they looked at the threat of losing credit card information. Then they looked at the supposed impact of the attack and since they had not detected anything the executives thought the countermeasures to fix the server was not necessary. The problems in the information security and risk management domain are that their procedures are not up to date and that most of the time the company was not worried about fixing the problem but trying to stop bad PR. Also, another problem is that they need to train their security professional by letting him work with a more experienced professional and not by himself. They could have potentially done better or responded quicker if they had trained personnel with him to

Open Document