preview

Questions On The Customer 's Data

Decent Essays

B. The Customer’s Data 1. Services & Applications a) The company relies upon an email service provided by their ISP. This practice places the company in the position of relying upon the ISP to properly protect, maintain and archive their email communications. Without specific and detailed service-level agreements with the ISP, the company may have little to no recourse in the case of data loss at the ISP. In addition, this introduces an external third party into the administration of the company’s services and business applications. b) Business Applications must be kept current with relevant patches and updates, which are applied quickly, methodically and uniformly across the devices in the network. Failing to keep software current …show more content…

Organizational data is vulnerable to loss when the primary data storage method is no longer accessible or available. Primary records can become unavailable due to many causes. Data can be stolen, become corrupted, get deleted (intentionally or accidentally), or just be unreachable because the user who has the data on their machine is away from work. One of the increasing threats on the internet is called “ransomware”. When a system is infected with CryptoLocker, a common form of ransomware, it detects and encrypts files on any directly connected (internal or external), shared or network storage drive accessible to the computer with asymmetric encryption [16]. The malware then sends the decryption key to the attacker, and informs the user that a ransom must be paid in order to regain access to their data. Paying the ransom is no guarantee that the attackers will deliver the decryption key to the data owner [16]. C. The Company (Regulatory Compliance & Policies) 1. Federal: The following are a sampling of federal laws that often apply to businesses that maintain an individual’s personal and financial information. The company currently does not have the infrastructure in place to be in compliance with these laws. a) The Federal Rules of Civil Procedure (FRCP), Title V, Disclosures and Discovery, Rule 34, specifies that a party in a civil procedure be able: “to produce and permit the requesting party or its

Get Access