Review and reflect on the knowledge you have gained from this course. Based on your review and reflection, write at least 3 paragraphs on the following:

profileMichelle_Michy
IncidentManagement.edited11.docx

Running Head: INCIDENT MANAGEMENT 1

INCIDENT MANAGEMENT 4

Incident Management

Name

Course

Tutor

Date

Incident Management

Every second count when an incident occurs. Malware infections spread rapidly and can cause catastrophic damages if not well managed. They can compromise accounts that are then used to escalate the damage, leading the further attack to sensitive assets. An effective incident team is critical in this moment in ensuring that an organization is back on its feet after the attack (Shackelford et al., 2016). During cybersecurity incidents, the response team may face significant pressure that alters their objectives. Periodic training can adequately equip the teams with the necessary skills and experience for responding to the incidents. The efforts should focus on achieving specific main objectives of management. They should include the following objectives:

Incident Detection

This objective involves the identification of a security incident. The response team should embark on research to explore the attack in detail. Sufficient information should be gathered concerning the situation. The entry point should be examined as fast as possible, as well as the breadth of the breach (Vasiu & Vasiu, 2018). This objective is eased and quickened by availing all the security tools to filter into a single location. An organization can install an intrusion detection system (IDS) on the network. Although it does not offer additional security, it is significant in the identification of the attacks on the system. The system can be configured to monitor specific activities and alert the incident response team in an event a threat is detected.

Handling

Incident handling should include processes like malware analysis, packet-sniffing, and other related actions that risk contaminating the machines used in the response. It is recommended that each team member has at least two computing devices, like laptops. Incident analysis resources can support the handling process (Vasiu & Vasiu, 2018). Some of the examples include the current baseline of projected system, applications and systems, and port lists. Others include laptops, workstations for digital forensic, and blank removable media. Some critical communication facilities for the handlers should be provided. Examples include contact information, encryption software, and incident reporting mechanisms.

Response

A security incident is likened with a forest fire. After it is detected together with the source, the event has to be contained to prevent further damage. The incident response team disables the network access for computers that are identified to have been infected by malware or viruses. The machines are quarantined, and security patches are installed. This process removes network vulnerabilities and resolves malware issues. Another response may be resetting the password for users whose accounts were breached. The accounts for insiders that may have caused the incident are blocked.

Recovery

This objective entails efforts of making an attacked organization operational again. The response team should back up all the affected systems to maintain their current state for later investigation. A system network validation is a critical effort at this stage (Shackelford et al., 2016). It should be accompanied by testing to ensure all systems are operational. Any component that was compromised should be recertified as secure and functional. The response team should install a long-term containment strategy that goes beyond returning all the system to production for regular business activities. The recovery needs to include a lockdown of a purge to user accounts and backdoors that can facilitate intrusion.

Sustainability

The objective of sustainability is to ensure that the changes made will be maintained in the long run. The process also ensures that the system is more secure than before from future attacks as an organization moves to a risk-based approach. The efforts need to include periodic and rigorous security testing, especially in high-risk areas such as the machines that have previously been attacked. An application security testing framework strengthens the cybersecurity plan for an organization. It is also critical in the sustainability of the security plan in preventing future attacks.

References

Shackelford, J. S, Fort, L. T & Charoen, D. (2016). Sustainable cybersecurity: Applying lessons from the green movement to managing cyber attacks. Retrieved from https://illinoislawreview.org/wp-content/uploads/2016/10/Shackelford.pdf

Vasiu, L & Vasiu, L. (2018). Cybersecurity as an essential sustainable economic development factor. European Journal of Sustainable Development, 7(4): 171-178. Retrieved from https://pdfs.semanticscholar.org/859d/47f06042805b97e8a4b84728cc6b8ea99681.pdf

R

u

n

n

i

n

g

H

e

a

d

:

I

N

C

I

D

E

N

T

M

A

N

A

G

E

M

E

N

T

1

Incident

M

anagement

Name

Course

Tutor

Date