Please assist me with this question for lab 9 of security risk managment: 14.) I
ID: 3747617 • Letter: P
Question
Please assist me with this question for lab 9 of security risk managment: 14.) In your Lab Report file, describe your personal procedures in terms of your RTO as explained in Web sites visited earlier in this lab.
My personal steps:
1.) If the lab files become corrupted, then an RTO to recover the particular files will need to be defined. For this lab, the RTO scenario is 15 minutes.
2.) The amount of space allowed is 10GB.
3.) Sent off Lab backup files via email (Sent at 3pm Eastern time)
4.)Received backup files via email 2 (Received at 3:01 Easter time)
5. Unzip the labs took 2 minutes to extract and replace. (If encrypted this process takes longer)
6.) Took an additional 3 minutes to scan the files for any malicious content.
7.) Verified the receipt of the email, along with the integrity of the files.
8.) The total amount of time to recover in the scenario was 6 minutes, to send and receive files, extract/scan files, check integrity of files, and restore files to location. Allotted time was 15 minutes 15/6 minutes gives us 11 minutes to spare. (This was using a fast-wired network connection).
9.) Same experiment was conducted on wireless 60mbps ~ took 9 minutes. Then tested again on a slow wireless connection 8mbps ~ took 18 minutes.
10.) Location is important to meet the RTO if a slow connection is used the RTO will be missed. Location can also affect security and integrity. Using an unsecure network, I was able to trace and see all files and information that we would not want anyone to get ahold of this data.
Please help me with this.
Websites visited:
https://www.bluelock.com/blog/rpo-rto-pto-and-raas-disaster-recovery-explained/
https://www.computerweekly.com/feature/How-to-write-a-disaster-recovery-plan-and-define-disaster-recovery-strategies/
Explanation / Answer
Risk management involves asset identification, classification and valuation.
Assessing the overall risk of the asset.There are several formal methods for doing ;this including qualitative and quantitative risk analysis countermeasures should be both technical and operational, using a blend of network systems and data controls evrything from system hardening to networkpartitoning.
using a blend of host and network based IDSes as well as both signature and anamoly based scanners.
An IR plan kicks in at different levels depending on the severity of attack and organizations.