preview

Impact Of Occurrence : Major Disasters And Major Impact On Earnings And / Or Company Image

Decent Essays

Impact of Occurrence: Major The threat event could be expected to have a potential for widespread disruption of operations and major impact to earnings and/or company image. Again, using Cloud AD as an example, if changes were to be made to corrupt the Active Directory structure every application using it for authentication and access would fail. Another example would be if an employee created an account it could be hidden and used later as a back door. Someone with elevated permissions could also delete one or more organizations from the directory causing varying degrees of service disruptions. Risk Score: High Mitigations 1. Grant elevated access only when required Perform user reviews and ensure that elevated access is only granted to those individuals who need it and have the knowledge to correctly use it. Do not grant permissions with a broad stroke. For example, if someone only needs permission to add an account to a group, grant the “add to user group permission”, not Domain Administrator permission. 2. Implement two factor authentication All administrative or root accounts on SPCComputing Infrastructure should utilize two factor authentication as a mechanism or authenticating accounts. Two factor authentication implements the concept of one time passwords and rendering an account useless to someone who was able to determine a password but did not have the token. 3. Administrative or root access should only be used when required All users should be logging on to

Get Access