Softsearch Case Study

1973 Words8 Pages
Softsearch Case Study Introduction You have recently been hired to serve as the chief information security officer (CISO) for Softsearch, a small game programming company based in Dallas, Texas. Branch offices are located in Albuquerque, New Mexico and Phoenix, Arizona. The company employs approximately 50 programmers, as well as office support staff and regular business staff, which includes an accounting department. The company does not employ outside marketing or legal staff. Softsearch typically releases three adventure and simulation titles per year on three major gaming systems and for PCs. Most of the programmers have been employed with Softsearch since its inception in 1998. Softsearch has conducted a risk management assessment of its computer systems and has found that there has been some abuse of personal e-mail, use of company information for personal reasons, and improper access of files on the network. In addition to the risk management assessment, the organization also used a vulnerability scanner that actually targets its system to try to identify holes within the system. (For results of the vulnerability scan, see Appendix A.) The scanner is an open source scanner called Nessus. Nessus is inexpensive and does not become a system hog like many vulnerability scanners. Management has decided to post employee guidelines to prevent further abuse of the systems and to state clearly what computer and network usage each employee will have. Additionally, management has decided to implement more security in the company. The current security budget for the new security system is $50,000. Recently, several of the ideas generated by Softsearch have also been developed at rival gaming companies. This leads the company to believe that there is either a flaw in its networking system or there is a leak in the company. The company has decided to create a more secure

More about Softsearch Case Study

Open Document