business continuity plan and disaster recovery plan ( i need this in 1 hr 20 mints ASAP)and exactly how the professor is asking

profilezoheb khan
Chapter8_IncidentResponse_RecoveryandMaintenancez1.pdf

Principles of Incident Response and

Disaster Recovery, 2nd Edition

Chapter 8 Incident Response: Recovery and

Maintenance

Objectives

• Describe how an organization plans for and executes the recovery process when an incident occurs

• Explain the need for and steps involved in the ongoing maintenance of the IR plan

• List the steps involved in collecting digital evidence • Discuss the process used to analyze evidence • Explain how encryption can thwart digital forensic

analysis

Principles of Incident Response and Disaster Recovery, 2nd Edition 2

Introduction

• Incident recovery can begin – Once the incident has been contained and system

control has been regained • First task

– Inform the appropriate human resources • CSIRT

– Must assess the full extent of the damage to determine what must be done to restore the systems

Principles of Incident Response and Disaster Recovery, 2nd Edition 3

Recovery

• Incident damage assessment – Initial determination of the scope of the breach of

confidentiality, integrity, and availability of information and information assets

– Can take days or weeks, depending on the extent of the damage

– Damage can range from minor to severe

Principles of Incident Response and Disaster Recovery, 2nd Edition 4

Identify and Resolve Vulnerabilities

• Forensics – Used for intrusion analysis and as part of evidence

collection and analysis – Also used to assess how the incident occurred and

what vulnerabilities were exploited to cause the assessed damage

• After any incident – The organization should address the safeguards that

failed to stop or limit the incident

Principles of Incident Response and Disaster Recovery, 2nd Edition 5

Restore Data

• The IR team must: – Understand the backup strategy used by the

organization – Restore the data contained in backups – Use the appropriate recovery processes from

incremental backups or database journals to recreate any data that was created or modified since the last backup

Principles of Incident Response and Disaster Recovery, 2nd Edition 6

Restore Services and Processes

• Compromised services and processes must be examined, verified, and then restored

• If services or processes were interrupted in the course of regaining control of the systems, they need to be brought back online

• An organization should continuously monitor its system

Principles of Incident Response and Disaster Recovery, 2nd Edition 7

Restore Confidence Across the Organization

• The IR team may wish to: – Issue a short memorandum outlining the incident

and assuring everyone that the incident was handled and the damage was controlled

• Objective of this communication – To prevent panic or confusion from causing

additional disruption to the operations of the organization

Principles of Incident Response and Disaster Recovery, 2nd Edition 8

Maintenance

• Maintenance of the IR plan includes: – Procedures to complete effective after-action review

meetings – A process to complete comprehensive periodic plan

review and maintenance – Efforts to continue the training of staff members who

will be involved in IR

Principles of Incident Response and Disaster Recovery, 2nd Edition 9

After-Action Review

• This is a detailed examination of the events that occurred, from first detection to final recovery

• Should be completed immediately after the events in question have been completed

• The entire AAR should be recorded for use as a training case for future staff

Principles of Incident Response and Disaster Recovery, 2nd Edition 10

After-Action Review (cont’d.)

• Use AAR to document lessons learned and generate IR plan improvements – Examining the documentation of the incident should

reveal • The point at which the incident was first detected • The point in time that the IR plan was enacted • How the first responders and CSIRT reacted

Principles of Incident Response and Disaster Recovery, 2nd Edition 11

After-Action Review (cont’d.)

• AAR as historical record of events – This may or may not be a requirement for legal

proceedings • AAR as a case training tool

– Even in defeat, the organization must continue to rebuild its defenses to fight another day

• AAR as closure – The AAR serves as closure to an incident

Principles of Incident Response and Disaster Recovery, 2nd Edition 12

Plan Review and Maintenance

• Questions that might be useful in this review – Has there been any use of this plan in the past

review period? – Were any AAR meetings held, and have the minutes

of any such meetings been reviewed to note deficiencies that may need attention?

– Have any other notices of deficiency been submitted to the plan owner, and have they been addressed yet?

Principles of Incident Response and Disaster Recovery, 2nd Edition 13

Training

• A systematic approach to training is needed to support the IR plan

• Cross-training – Is needed to be assured that enough staff members

with the proper skills are available for all realistic scenarios

Principles of Incident Response and Disaster Recovery, 2nd Edition 14

Rehearsal

• Plans should be rehearsed until those responding are prepared for the actions they are expected to perform

• Rehearsal adds value by: – Exercising the procedures – Identifying any shortcomings – Providing the opportunity to improve the plan before

it is needed

Principles of Incident Response and Disaster Recovery, 2nd Edition 15

Law Enforcement Involvement

• When an incident violates civil or criminal law – It is the organization’s responsibility to notify the

proper authorities • Law enforcement agencies

– Usually better equipped at processing evidence than a business organization

• Disadvantage of law enforcement involvement – Possible loss of control of the chain of events

following an incident

Principles of Incident Response and Disaster Recovery, 2nd Edition 16

Reporting to Upper Management

• After preliminary assessment, the CSIRT leader should: – Make a report to upper management, typically the

CISO and CIO • Upper management

– Usually requests assistance in drafting a press release to notify the general public and a specific notification to any stakeholders affected by the event

Principles of Incident Response and Disaster Recovery, 2nd Edition 17

Loss Analysis

• In determining the costs associated with an incident, consider: – Cost associated with the number of person-hours

diverted from normal operations to react to the incident

– Cost associated with the number of person-hours needed to recover data

– Opportunity costs associated with the number of person-hours that could have been devoted to working on more productive tasks

Principles of Incident Response and Disaster Recovery, 2nd Edition 18

Loss Analysis (cont’d.)

• In determining the costs associated with an incident, consider (cont’d.) – Cost associated with reproducing lost data (if

possible) – Legal cost associated with prosecuting offenders (if

possible) – Cost associated with loss of market advantage or

share due to disclosure of proprietary information – Cost associated with acquisition of additional

security mechanisms ahead of budget cycle

Principles of Incident Response and Disaster Recovery, 2nd Edition 19

Incident Forensics

• Forensics – The use of methodical technical investigation and

analysis techniques to identify, collect, preserve, and analyze objects and information of potential evidentiary value

• Computer forensics – The use of forensics techniques when the source of

evidence is a computer system • Digital forensics

– The use of forensic techniques when the source of evidence is a digital electronic device

Principles of Incident Response and Disaster Recovery, 2nd Edition 20

Legal Issues in Digital Forensics

• Private organizations should employ the following procedure when searching an employee’s computer – Verify that organizational policy allows such a search

to occur – Verify that the search is “justified at its inception” – Verify that the search is “permissible in its scope” – Verify that the organization has clear ownership over

the container the material was discovered in – Verify that the search has been authorized by a

manager or administrator in the appropriate chain of command

Principles of Incident Response and Disaster Recovery, 2nd Edition 21

Digital Forensics Team

• When planning a forensics operation, an organization should consider: – Cost – Response time – Data sensitivity

• Division of forensic functions – First response – Analysis and presentation

Principles of Incident Response and Disaster Recovery, 2nd Edition 22

Digital Forensics Team (cont’d.)

• First response team – Incident manager, scribe, and imager

• Analysis team – Forensic analysis function: examination and analysis – Forensic examiners

• Skilled in the operations of particular tools – Forensic analysts

• Know about operating systems and networks

Principles of Incident Response and Disaster Recovery, 2nd Edition 23

Digital Forensics Team (cont’d.)

• Some of the contents of a forensic field kit – Forensic laptops that have multiple operating systems – Call list with subject-matter experts in various IT

technologies – Cell phones with extra batteries and chargers – Hard drives, blank CDs, blank DVDs, and USB flash

drives – Imaging software or hardware with write blockers – Forensic software and tools – Cables, extension cords, and power strips – Evidence bags, seals, and permanent markers

Principles of Incident Response and Disaster Recovery, 2nd Edition 24

Principles of Incident Response and Disaster Recovery, 2nd Edition 25

Digital Forensics Methodology

• A digital investigation usually begins with some allegation of wrongdoing

• Assessing the scene involves: – Interviewing the key contacts who are present and

documenting the scene – Methods used include photography and field notes

Principles of Incident Response and Disaster Recovery, 2nd Edition 26

Principles of Incident Response and Disaster Recovery, 2nd Edition 27

Principles of Incident Response and Disaster Recovery, 2nd Edition 28

Principles of Incident Response and Disaster Recovery, 2nd Edition 29

Digital Forensics Methodology (cont’d.)

• Acquiring the evidence – An organization’s IR policy must spell out the

procedures for initiating the investigative process – Digital evidence collection follows a simple four-step

methodology • Identify sources of evidentiary material • Authenticate the evidentiary material • Collect the evidentiary material • Maintain a documented chain of custody

Principles of Incident Response and Disaster Recovery, 2nd Edition 30

Digital Forensics Methodology (cont’d.)

• Identifying sources – Information may reside on:

• Disks in a desktop and/or laptop computer • Disks in external storage enclosures • Memory sticks or cards • PDA • Cellular phone • Storage devices, such as MP3 players • Optical storage, such as CDs and DVDs • Networked storage

Principles of Incident Response and Disaster Recovery, 2nd Edition 31

Digital Forensics Methodology (cont’d.)

• Authenticating evidence – Cryptography

• One way to identify a particular digital item – When a piece of digital evidence is collected, its

hash value is calculated and recorded – Hashes are acceptable for demonstrating the

integrity of digital evidence – NIST is developing new hash algorithms that will be

more resistant to attack

Principles of Incident Response and Disaster Recovery, 2nd Edition 32

Digital Forensics Methodology (cont’d.)

• Collecting evidence – The investigator must make no changes to the

evidence – Evidence labels and seals are crucial to prevent

doubts on evidence handling – All sterilization procedures must be codified – All media sterilization processes must be

documented

Principles of Incident Response and Disaster Recovery, 2nd Edition 33

Principles of Incident Response and Disaster Recovery, 2nd Edition 34

Principles of Incident Response and Disaster Recovery, 2nd Edition 35

Digital Forensics Methodology (cont’d.)

• Collecting evidence (cont’d.) – In a dead acquisition

• The computer is typically powered off so that its disk drives can be removed for imaging

• An investigator seeks to obtain a forensic image of the disk or device

– When making a forensic image of a device • Forensic investigators use bitstream copying

– Write blockers • Devices that allow acquisition of information on a drive

without creating the possibility of accidentally damaging the contents

Principles of Incident Response and Disaster Recovery, 2nd Edition 36

Principles of Incident Response and Disaster Recovery, 2nd Edition 37

Digital Forensics Methodology (cont’d.)

• Maintaining a documented chain of custody – Chain of custody

• A legal record of where the evidence was at each point in its lifetime and documentation of each and every access to it

– The storage facility requires • Controlled temperature and humidity • Freedom from strong electrical and magnetic fields

that might damage the items • Protection from fire and other physical hazards

Principles of Incident Response and Disaster Recovery, 2nd Edition 38

Principles of Incident Response and Disaster Recovery, 2nd Edition 39

Digital Forensics Methodology (cont’d.)

• Analyzing evidence – First step is to obtain the evidence from the storage

area and perform physical authentication – Disk images must be loaded into the particular

forensic tool used by the organization – Two common tools used in forensic analysis

• Forensic Toolkit (FTK) from AccessData • EnCase from Guidance Software

Principles of Incident Response and Disaster Recovery, 2nd Edition 40

Digital Forensics Methodology (cont’d.)

Principles of Incident Response and Disaster Recovery, 2nd Edition 41

Digital Forensics Methodology (cont’d.)

• Analyzing evidence (cont’d.) – FTK

• Performs extensive pre-processing of evidence items • Organizes the various items into a tabbed display • Constructs an index of terms found in the image as

part of preprocessing – EnCase forensic edition

• Presents an extensible forensic platform that makes it easy for trained investigators to carry out their tasks

• Supports EnScripts

Principles of Incident Response and Disaster Recovery, 2nd Edition 42

Principles of Incident Response and Disaster Recovery, 2nd Edition 43

Principles of Incident Response and Disaster Recovery, 2nd Edition 44

Digital Forensics Methodology (cont’d.)

• Reporting the findings – Once the analysis is complete, the findings must be

reported in written and often verbal form – People who will use the report

• Upper management • Forensic expert retained by the opposition • Attorneys, judges, and juries • Other professionals (auditors, heads of human

resources departments, and others)

Principles of Incident Response and Disaster Recovery, 2nd Edition 45

eDiscovery and Anti-Forensics

• Discovery – One party can obtain evidence from the opposing

party through specific requests for information • eDiscovery

– The search for, collection, and review of items stored in electronic format that are of potential evidentiary value based on criteria specified by a legal team

• Anti-forensics – An attempt made by those who may become subject

to digital forensic techniques to hide items of evidentiary value

Principles of Incident Response and Disaster Recovery, 2nd Edition 46

eDiscovery and Anti-Forensics (cont’d.)

• Organizations must be aware that: – Forensic tools are not just in the hands of honest

professionals, they are available to everyone • Encrypted information

– Poses significant challenges to forensic investigators because, by its nature, encryption conceals the content of digital material

• Some forensic products – Offer brute force attacks against the encrypted

information, using dictionaries of common pass phrases

Principles of Incident Response and Disaster Recovery, 2nd Edition 47

Principles of Incident Response and Disaster Recovery, 2nd Edition 48

Summary

• IR begins once an incident has been contained and system control has been regained

• After any incident, address the safeguards that failed to stop or limit the incident

• Compromised services and processes must be examined, verified, and then restored

• Ongoing maintenance includes – After-action review (AAR) meetings – Planning review and maintenance – Training of staff members

Summary (cont’d.)

• When plan shortcomings are noted, the plan should be reviewed and revised

• A systematic approach to training is needed to support the IR plan

• A digital investigation begins with an allegation of wrongdoing

• First-response digital forensic team – Secures and collects the devices, media, or media

images that are potentially evidentiary

Principles of Incident Response and Disaster Recovery, 2nd Edition 49

Summary (cont’d.)

• Forensic tools – Can be used by investigators even to obtain

information that has been deleted from digital media • eDiscovery

– The search for, collection, and review of items stored in electronic format that are of potential evidentiary value

• Anti-forensics – The attempt by those who may become subject to

digital forensics techniques to hide items of evidentiary value

Principles of Incident Response and Disaster Recovery, 2nd Edition 50

  • Principles of �Incident Response and Disaster Recovery, 2nd Edition
  • Objectives
  • Introduction
  • Recovery
  • Identify and Resolve Vulnerabilities
  • Restore Data
  • Restore Services and Processes
  • Restore Confidence Across the Organization
  • Maintenance
  • After-Action Review
  • After-Action Review (cont’d.)
  • After-Action Review (cont’d.)
  • Plan Review and Maintenance
  • Training
  • Rehearsal
  • Law Enforcement Involvement
  • Reporting to Upper Management
  • Loss Analysis
  • Loss Analysis (cont’d.)
  • Incident Forensics
  • Legal Issues in Digital Forensics
  • Digital Forensics Team
  • Digital Forensics Team (cont’d.)
  • Digital Forensics Team (cont’d.)
  • Slide Number 25
  • Digital Forensics Methodology
  • Slide Number 27
  • Slide Number 28
  • Slide Number 29
  • Digital Forensics Methodology (cont’d.)
  • Digital Forensics Methodology (cont’d.)
  • Digital Forensics Methodology (cont’d.)
  • Digital Forensics Methodology (cont’d.)
  • Slide Number 34
  • Slide Number 35
  • Digital Forensics Methodology (cont’d.)
  • Slide Number 37
  • Digital Forensics Methodology (cont’d.)
  • Slide Number 39
  • Digital Forensics Methodology (cont’d.)
  • Digital Forensics Methodology (cont’d.)
  • Digital Forensics Methodology (cont’d.)
  • Slide Number 43
  • Slide Number 44
  • Digital Forensics Methodology (cont’d.)
  • eDiscovery and Anti-Forensics
  • eDiscovery and Anti-Forensics (cont’d.)
  • Summary
  • Summary (cont’d.)
  • Summary (cont’d.)