My WebLink
|
Help
|
About
|
Sign Out
Browse
Search
AgdaPkt 2020-12-21 Amended Joint SA PFA
RedwoodCity
>
City Clerk
>
Agenda Packets
>
2020-2029
>
2020
>
AgdaPkt 2020-12-21 Amended Joint SA PFA
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
1/5/2021 12:51:59 PM
Creation date
12/18/2020 5:45:35 PM
Metadata
Fields
Template:
CC Index
CC Index - Document Type
Agenda Packet
Meeting Type
Joint
Agency Type
City Council and Successor Agency and Public Financing Authority
Date
12/21/2020
Jump to thumbnail
< previous set
next set >
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
1000
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
Show annotations
View images
View plain text
6.D. - Page 14 of 33 <br />Given the usual secrecy involved in most malware incursions, the following description of this <br />IT manager's actual experience is instructive since it offers an example of "best practices" that <br />can guide others anticipating or facing a Ransomware threat.20 <br />This organization suffered two serious breaches less than two months apart and successfully <br />recovered both times. In the first breach, within 45 minutes of a user clicking on an email <br />attachment, the Crypto virus had spread to 12 of the organization's 23 servers. The IT Manager <br />was alerted to the problem both by the user whose PC was locked with the Ransomware demand <br />on his screen and an auto alert from the network scanning software that reported unusual activity. <br />The IT Manager's first action was to rapidly shut down the entire server network. This of course <br />stopped the spread of the virus, but also prevented users from performing their jobs. Fortunately, <br />their backup strategy implementation worked well as they were able to fully recover within <br />hours. <br />The major components of the protection strategy employed included: <br />• Separating the network into discrete departments or segments (creating subnets) which <br />restricted individuals' access to only servers containing their department's software and <br />network storage. This limited the spreading of the virus across various departments <br />within the organization. The analogy is a modern ship with rooms and decks that can be <br />completely closed off from each other in the event of a fire or explosion. <br />• Taking snapshots (copies) of their Storage Area Network (SAN) twice a day. <br />• Completing full nightly backups of their SQL databases and incremental backups of the <br />databases at five-minute intervals. <br />• Performing server backups with a commercial external backup appliance and/or service. <br />See Appendix D for examples of companies in this market.21 <br />• Regularly testing the restore process to ensure the successful recovery of critical server <br />hardware. Without testing, there is no assurance that the Cybersecurity plan will work. <br />Moreover, even if it works once, that is no assurance it will work again, without periodic <br />re -testing. <br />• Conducting weekly backups of critical personnel's full PC hard drives. <br />• Use the "3-2-1 strategy"22: do three backups into two different media including one <br />offsite. <br />Having all of these Cybersecurity plan components was a good start but it took much more to <br />affect a recovery. First a commercial Virus Removal Software Tool was used which did not <br />work (in this case). Therefore, the IT team used the snapshot copies to replace corrupted data on <br />infected server units followed by the application of the incremental backups of the database to <br />complete the restore. <br />20 Grand Jury Interview <br />21 These services include onsite and offsite backup and recovery services which are usually located outside the <br />immediate locale. <br />22 Management Wire, The 3-2-1 Backup Rule and Effective Cybersecurity Strategy, January 7, 2020. <br />2019-2020 San Mateo County Civil Grand Jury 6 <br />135 <br />
The URL can be used to link to this page
Your browser does not support the video tag.