Cmgt 582 Security and Ethics - Law and Ethics, discussion help

User Generated

ibaoebja

Computer Science

Description

Running Case 4D: Running Case: Stratified Custom Manufacturing 

 Drew Cubbins was not happy as he left the meeting. He often found himself in a bad mood after any meeting that involved attorneys. This event was no exception. SCM faced a civil suit from one of its business partners who claimed they were the victim of a cyber attack launched from yet another of SCM’s business partners. The firm initiating the suit was Bullard Enterprises, a subassembly parts supplier. The third party, Caldwell Supply, was the firm that was first completely compromised or pwned1 by the attackers and then whose systems and networks were used by the attackers to launch a second, more lucrative attack against Bullard Enterprises.

Bullard Enterprises was suing SCM under the theory of downstream liability, claiming SCM should have enforced more stringent controls on the shared wide area network used by SCM and its various business partners. SCM had published a set of network-recommended practices for its vendor interconnection network, but these standards were only loosely enforced and no one could ever recall a potential business partner being denied access to the network for a failure to comply with the recommendations.

Drew had just finished a meeting with his own lawyers in which they were attempting to craft a strategy for their defense in this suit. He was pretty sure they were going to lose the suit and pay substantial damages to Bullard.  

Now, his thoughts were on what to do with the vendor network and how to make it more secure without incurring too much in the way of expenses for that effort. It would no doubt require the buy-in from every one of the major suppliers and money and resources from SCM. He considered his options and then came to the conclusion that Takio Sumi, the CIO of SCM, would have to take point on this project.

Please answer the following question below by providing your response:

Pretend you are listening in on the meeting with Drew Cubbins and Takio Sumi. What would be the main points of the conversation?

Main Point #1 --  What steps need to be taken to ensure the network is more secure and the company no longer liable for damages? 

#2 -- How much of these steps can be shared responsibilities with the partners? 

#3-- How do we get the partner companies on board with SCM? 

#4 -- What can be put in place to enforce compliance in the future?


User generated content is uploaded by users for the purposes of learning and should be used following Studypool's honor code & terms of service.

Explanation & Answer


Anonymous
I was having a hard time with this subject, and this was a great help.

Studypool
4.7
Trustpilot
4.5
Sitejabber
4.4

Related Tags