HOME | Threat and Vulnerability Management Policy

Threat and Vulnerability Management Policy

EBI Consulting utilizes multiple approaches to protect EBI, Clients, Employees and Systems from internal and external threats and vulnerabilities.

1. Tools and Services

Utilize a combination of tools for comprehensive protection, including:

  • Managed Detection and Response (MDR) service provider for real-time monitoring and incident response.
  • Multiple email Scanning service providers to prevent phishing, malware, and spam.
  • Virus and Malware Prevention/Scanning software on all devices and endpoints.

2. Vulnerability Scanning

Daily Scans:

  • Conduct daily vulnerability scans on all devices to detect potential threats or weaknesses.
  • Review and respond to any high or critical vulnerabilities identified during daily scans.

Weekly Scans:

  • Perform full-system scans on all devices weekly to ensure thorough coverage of all systems.
  • Review and respond to reports from weekly scans and prioritize vulnerability patching based on severity and risk impact.

3. Patch Management

  • Patch systems on a bi-weekly basis with a staggered deployment to avoid downtime or disruptions to business operations.
  • Prioritize critical security patches and ensure they are deployed within 48 hours of release.
  • Test patches in a development environment before deployment in production to prevent compatibility issues.

4. Threat Detection and Response

  • The MDR service continuously monitors the network and endpoints for suspicious activity, ensuring rapid detection and response to potential threats.
  • Alerts from the MDR are triaged, and incidents are escalated for investigation based on severity.
  • For confirmed threats, follow the Incident Response Plan to contain, eradicate, and recover from the attack.

5. Email Security

  • Utilize email scanning solutions to block phishing attacks, malicious attachments, and suspicious links.
  • Utilize email phishing training campaigns to identify where further training is required.
  • Train employees in safe email practices and how to recognize phishing or any other malicious attempt.

6. Roles and Responsibilities:

IT Security Team:

  • Responsible for configuring and maintaining the MDR service, virus/malware scanning and protection tools, and vulnerability management processes.
  • Monitor vulnerability reports and take appropriate actions based on threat severity.
  • Point of escalation, management, and remediation for all cyber security or other potential systems or data risks.
  • Ensure that patches and updates are deployed within the required timelines.
  • Maintain the infrastructure and ensure all systems comply with the organization’s security policies.

Employees:

  • Realize and adhere to their role in protecting themselves, the company and clients from unwanted actions.
  • Responsible for reporting suspicious emails, links, or behaviors to the IT team.
  • Participate in regular security awareness training and adhere to safe email and internet usage practices.