Phoenix project

    Master this deck with 22 terms through effective study methods.

    Generated from uploaded pdf

    Created by @Testing

    What was the immediate response to the intrusion at UVA?

    The immediate response involved initiating a covert project called Phoenix, led by German as the project manager, to address the security breach.

    What were the high-level objectives of the Phoenix Project?

    The high-level objectives included determining the extent of the intrusion and developing a remediation plan to address system deficiencies.

    Why was it necessary to go dark during the remediation process?

    Going dark was necessary to turn off UVA's Internet connection for several days to allow rebuilt servers to come online, remove compromised accounts, and prevent attackers from moving to other systems.

    Who was responsible for managing the project team structure?

    German was responsible for managing the project team structure, leveraging Evans's support and experience in managing major IT projects.

    What quote from Apollo 13 was cited to emphasize the mission's importance?

    Hogan cited the quote 'Failure is not an option' from Apollo 13 to underscore the critical nature of their mission.

    How many people were involved in the Phoenix Project?

    A total of 176 people were involved in the Phoenix Project, making it challenging to maintain agility and secrecy.

    What measures were taken to ensure secrecy among team members?

    New team members had to be sworn to secrecy before being briefed on the project, and all communication was conducted outside of UVA's systems using Google Gmail and Google Docs.

    Where was the meeting site for the project team located?

    The meeting site was a repurposed vacant building situated in a relatively private area close to the main ITS offices.

    What facilities were provided at the meeting site for the project team?

    The meeting facility functioned as a 'war room' equipped with all requisite technology, whiteboards, and a continuous supply of refreshments.

    What was the significance of the first meeting of the team leaders?

    The first meeting was significant as it briefed team leaders on the mission's importance and set the tone for the project's urgency and seriousness.

    What was the first decision made regarding the remediation plan?

    The first decision was to schedule a go-dark phase to facilitate the remediation process.

    How did the team leaders operate during the project?

    The team leaders operated as a 'team of teams,' following a well-orchestrated plan and schedule while remaining agile to respond to new information.

    What role did Evans play in the Phoenix Project?

    Evans played a crucial role by providing support, managing the project, and ensuring that the team was organized and focused on the mission.

    What challenges did the project face due to the number of people involved?

    The large number of participants made it challenging to maintain both agility and secrecy, requiring strict protocols for communication and information sharing.

    What was the purpose of the preliminary investigation conducted by Mandiant?

    The preliminary investigation aimed to assess the intrusion's extent before the more in-depth assessment initiated by the Phoenix Project.

    What was the ultimate goal of the remediation plan?

    The ultimate goal of the remediation plan was to address system deficiencies and ensure the security of UVA's IT infrastructure.

    How did the team ensure effective communication during the project?

    The team ensured effective communication by using external tools like Google Gmail and Google Docs to prevent detection by attackers.

    What was the significance of the term 'go-dark' in the context of the project?

    'Go-dark' referred to the decision to disconnect from the Internet to secure systems and prevent further intrusion during the remediation process.

    What strategies were employed to manage the complexity of the project?

    Strategies included creating a structured project team, assigning team leads, and holding daily meetings to coordinate efforts and address challenges.

    Why was it important for team members to be 'read-in' on the project?

    Being 'read-in' was important to ensure that team members were fully briefed on the project details while maintaining confidentiality and security.

    What was the role of technology in the project team's operations?

    Technology played a critical role in facilitating communication, collaboration, and project management, especially in a secure environment.

    How did the project team adapt to new information during the remediation process?

    The project team adapted by maintaining agility in their operations, allowing them to respond quickly to emerging information and challenges.