Sei sulla pagina 1di 13

CAREFUL

Information Security and Ethics


By Christopher Root

RSA CONFIDENTIALINTERNAL USE ONLY


1
BIO

Support Advisor (TSE III)


Utah Team Lead
Information Security specialist
Concerned citizen
Defender of client data

Copyright 2017 EMC Corporation. All rights reserved.


2
WHY DOES THIS MATTER?
PAST, PRESENT, FUTURE

The RSA Breach of 2011


Everyday Archer ethics
How would you react?

Copyright 2017 EMC Corporation. All rights reserved.


3
MARCH MADNESS

RSA hacked by spear-phishing attack

Products, brand, and integrity questioned

Millions of customers affected worldwide

Copyright 2017 EMC Corporation. All rights reserved.


4
RESPONDING TO PRESSURE

Zero-day attack via e-mail attachment


Breach

Social engineering/extensive planning


Analysis Information stolen and tracks covered

Notify and inform customers


Response Prevent future occurrences

Copyright 2017 EMC Corporation. All rights reserved.


5
DAILY DILEMMAS

Sales Figures
New Contracts
Internal Memos

Copyright 2017 EMC Corporation. All rights reserved.


6
ARCHER HURDLES

Databases
Data feeds and source files

Application packages

Copyright 2017 EMC Corporation. All rights reserved.


7
HOSTED CLIENTS

Password
resets

SaaS Requests
(ASRs)

Admin
Verification

Copyright 2017 EMC Corporation. All rights reserved.


8
HANDLING AN INCIDENT
MAKING THE RIGHT CHOICE

Office of
Direct
General Customer
Manager
Counsel

Copyright 2017 EMC Corporation. All rights reserved.


9
COVER YOUR ACTIONS
IF YOU KNOW OR SUSPECT A VIOLATION

Contact the Office of General Counsel by


telephone (508-435-1000 ext. 77267)
EMC hotline by telephone (877-764-
0557) or secure web report to
https://emccorporation.alertline.com
Business Conduct Guidelines located on
Inside Dell/EMC

Copyright 2017 EMC Corporation. All rights reserved.


10
QUESTIONS AND FEEDBACK

Feel free to contact me directly at


Christopher.Root@rsa.com

Thank you for listening!

Copyright 2017 EMC Corporation. All rights reserved.


11
SOURCES

Devanna, Toni. (2014, March 18). DellEMC Education Services.


Retrieved from Business Conduct Guidelines - English:
https://inside.dell.com/docs/DOC-93428

Savage, M. (2012, February). The RSA breach: One year later.


Retrieved from TechTarget:
http://searchsecurity.techtarget.com/magazineContent/The-
RSA-breach-One-year-later

Copyright 2017 EMC Corporation. All rights reserved.


12
EMC, RSA, the EMC logo and the RSA logo are trademarks of EMC Corporation in the U.S. and other countries.

Potrebbero piacerti anche