Topic: You are the CISO for a large-scale, publicly traded organization. What protections would you implement to ensure availability on your systems? And why?
The availability of a users information refers to the ease of access to receive the intended information. When dealing with a large-scale user base, applying software updates can affect a mass amount of users and prevent them from accessing their information for an extended period of time while the updates are being applied. In order to protect from this specific incident I could implement a warm site that has environmental conditions along with basic tech infrastructure to allow users to access the most important features, but at a slower processing speed. Another potential threat with the availability of information comes from a data breach where attackers attempt to take or corrupt user data. To protect against this threat, I would have multiple backups of user information to be able to bring the system back to a stable point as quickly as possible. This raises the question of how long should these backups be kept for. To combat this, monthly in-depth audits should be made to check for deleted user accounts with data still in remaining backups along with repairing any corrupt data from similar previous backups. Overall, having a warm-site allows the organization to redirect traffic temporarily while software/hardware updates are taking place in the active hot-site and having user backups helps prevent data loss in the event of a cyber incident. With this in mind though, those backups of user data should be audited regularly for corrupted or out-of-date data.