Team Assignment - Due 17 July at 1500est.

profileShiaRo
TeamAssignment-Group2.docx

UNAMED FOR NOW GROUP2 8

Group #2

By

University of Maryland University College

CSEC 661 9040 (2185)

Digital Forensics Investigations

Table of Contents Abstract 3 Introduction 4 Response Readiness Plan 4 Coordination Plan 5 Metrics 5 Conclusion 5 References 6

Abstract

This paper attempts to educate the reader on the importance of creating, maintaining and properly utilizing a response readiness, coordination plan as well as the metrics involved in the creation of the plans. Most information was derived from the NIST special publications…… and ….

A response readiness plan should effectively tell the organization what, when and how to protect the organization in a time of danger (or loss of data). A coordination plan should also details the steps….

Recommendations….

Most importantly an organization should be prepared to respond on a large scale to ….

No one can predict the future or how events beyond the control of an organization will affect its ability to operate when an incident strikes. The impact of data corruption or loss from hacking could be significant to the survival of the organization that manages large volumes of data pertinent to their business operations. The organization should analyze how to respond to a Large Environment Forensics incident where many people and devices may be involved

Introduction

The role of a first responder is very unique and important, normally they are the first to react in the time of a crisis situation. He or she should be prepared, with planned actions and directions, and a bonafide toolkit and most importantly “… a pre-determined incident response plan to follow…”, Branson et al (2005, p. 106). In the last Quarter Century, the business world has encountered/witnessed numerous Cyber Incidents, some organizations have been better prepared than others. For those that survive the incident all had one thing in common, which was a response plan, perhaps not the best but a plan is always better than no plan. Aside from a plan, when you dig below the surface you must also have the following:

Proper Tools and Equipment to respond

Trained people that know what to do, that are properly trained and know what to do with the equipment.

Proper certification that backup up the training.

And of course a proper plan and strategy

Response Readiness Plan

Along with a broad scope of guidelines manuals and directives, contingency planning brings forth “…a broad scope of activities designed to sustain and recover critical system services following an emergency event.”, Bowen et al (2010, p. 21). A formal policy is necessary in order to provide clarity and guidance for an effective contingency plan, however, to brass must be part of the concept “from start to finishas well as support and participation from senior managers, midlevel managers, and individual contributors.” , Balaouras et al (2009, p. 9). Though it is not mandatory it is highly recommended to use the NIST 800-86, “Its focus is primarily on using forensic techniques to assist with computer security incident response,…” NIST 800-86 (0000). It is also good to keep in mind that the NIST 800-86 is “presents forensics from an IT view, not a law enforcement view’, along with the knowledge that NIST 800-86.

Per NIST 800-86, Implemention of the following should maintain efficiency effectiveness:

· Organizations should ensure that their policies contain clear statements addressing all major forensic considerations, such as contacting law enforcement, performing monitoring, and conducting regular reviews of forensic policies and procedures.

· Organizations should ensure that their policies contain clear statements addressing all major forensic considerations, such as contacting law enforcement, performing monitoring, and conducting regular reviews of forensic policies and procedures.

· Organizations should ensure that their policies contain clear statements addressing all major forensic considerations, such as contacting law enforcement, performing monitoring, and conducting regular reviews of forensic policies and procedures.

· Organizations should ensure that their policies contain clear statements addressing all major forensic considerations, such as contacting law enforcement, performing monitoring, and conducting regular reviews of forensic policies and procedures.

· Organizations should include various teams from and throughout the organization, such as legal advisors and physical security staff, in some forensic activities.

NIST800-86 pg 2-1 thru 2-2

However, forensic tools and techniques are also useful for many other types of tasks, such as the following:

Operational Troubleshooting. Many forensic tools and techniques can be applied to troubleshooting operational issues, such as finding the virtual and physical location of a host with

 Log Monitoring. Various tools and techniques can assist in log monitoring, such as analyzing log entries and correlating log entries across multiple systems. This can assist in incident handling, identifying policy violations, auditing, and other efforts.

 Data Recovery. There are dozens of tools that can recover lost data from systems, including data that has been accidentally or purposely deleted or otherwise modified. The amount of data that can be recovered varies on a case-by-case basis.

 Data Acquisition. Some organizations use forensics tools to acquire data from hosts that are being redeployed or retired. For example, when a user leaves an organization, the data from the userís workstation can be acquired and stored in case it is needed in the future. The workstationís media can then be sanitized to remove all of the original userís data.

 Due Diligence/Regulatory Compliance. Existing and emerging regulations require many organizations to protect sensitive information and maintain certain records for audit purposes. Also, when protected information is exposed to other parties, organizations may be required to notify other agencies or impacted individuals. Forensics can help organizations exercise due diligence and comply with such requirements.

800-86 pg 2-2

Although the extent of this need varies, the primary users of forensic tools and techniques within an organization usually can be divided into the following three groups:5

·  Investigators. Investigators within an organization are most often from the Office of Inspector General (OIG)” at least from a government point of view. “Other investigators within an organization might include legal advisors and members of the human resources department.”

·  IT Professionals. This group includes technical support staff and system, network, and security administrators. They use a small number of forensic techniques and tools specific to their area of expertise during their routine work (e.g., monitoring, troubleshooting, data recovery).

·  Incident Handlers. This group responds to a variety of computer security incidents, such as unauthorized data access, inappropriate system usage, malicious code infections, and denial of service attacks. Incident handlers typically use a wide variety of forensic techniques and tools during their investigations.

· For example, some organizations perform standard tasks themselves and use outside parties only when specialized assistance is needed. Even organizations that want to perform all forensic tasks themselves usually outsource the most demanding ones, such as sending physically damaged media to a data recovery firm for reconstruction, or having specially trained law enforcement personnel or consultants collect data from an unusual source (e.g., cell phone).

· 2-3

· When deciding which internal or external parties should handle each aspect of forensics, organizations should keep the following factors in mind:

Cost. There are many potential costs. … Other significant expenses involve staff training and labor costs, which are particularly significant for dedicated forensic specialists.

Response Time. Personnel located on-site might be able to initiate computer forensic activity more quickly than could off-site personnel.

Data Sensitivity. Because of data sensitivity and privacy concerns, some organizations might be reluctant to allow external parties to image hard drives and perform other actions that provide access to data. For example, a system that contains traces of an incident might also contain health care information, financial records, or other sensitive data; an organization might prefer to keep that system under its own control to safeguard the privacy of the data.

It is also beneficial for incident handlers to have expertise in information security and specific technical subjects, such as the most commonly used OSs, filesystems, applications, and network protocols within the organization. Having this type of knowledge facilitates faster and more effective responses to incidents. Incident handlers also need a general, broad understanding of systems and networks so that they can determine quickly which teams and individuals are well-suited to providing technical expertise

On an incident handling team, more than one team member should be able to perform each typical forensic activity so that the absence of any single team member will not severely impact the teamís abilities. Incident handlers can train each other in the use of forensic tools and other technical and procedural topics. Hands-on exercises and external IT and forensic training courses can also be helpful in building and maintaining skills.

It is not feasible for any one person to be well-versed in every technology (including all software) used within an organization; therefore, individuals performing forensic actions should be able to reach out to other teams and individuals within their organization as needed for additional assistance.

In addition to IT professionals and incident handlers, others within an organization may also need to participate in forensic activities in a less technical capacity. Examples include management, legal advisors, human resources personnel, auditors, and physical security staff.

To facilitate inter-team communications, each team should designate one or more points of contact. These individuals are responsible for knowing the expertise of each team member and directing inquiries for assistance to the appropriate person. Organizations should maintain a list of contacts that the appropriate teams can reference as needed. The list should include both standard (e.g., office phone) and emergency (e.g., cell phone) contact methods.

2.4 Policies

Organizations should ensure that their policies contain clear statements that address all major forensic considerations, such as contacting law enforcement, performing monitoring, and conducting regular reviews of forensic policies, guidelines, and procedures.

The policy should clearly indicate who should contact which internal teams and external organizations under different circumstances. The policy should also discuss jurisdictional conflictsóa crime that involves multiple jurisdictions, which could be investigated by multiple law enforcement agenciesóand explain how to resolve them.

2.4.2 Providing Guidance for Forensic Tool Use

Although the technologies have many benefits, they can also be misused accidentally or intentionally to provide unauthorized access to information, or to alter or destroy information, including evidence of an incident.

To ensure that tools are used reasonably and appropriately, the organizationís policies, guidelines, and procedures should clearly explain what forensic actions should and should not be performed under various circumstances. For example, a network administrator should be able to monitor network communications on a regular basis to solve operational problems, but should not read usersí e-mail unless specifically authorized to do so.

2.5 Guidelines and Procedures

An organizationís forensic guidelines should include general methodologies for investigating an incident using forensic techniques, since it is not feasible to develop comprehensive procedures tailored to every possible situation.

Business records have normally been treated as equivalent to originals. Increasingly, some in the legal and forensic communities are concerned with the ease with which electronic records can be created, altered, or otherwise manipulated. In addition, various compliance initiatives in the public and private sectors are making it increasingly important to demonstrate the integrity of electronic records.

The guidelines and procedures should support the admissibility of evidence into legal proceedings, including information on gathering and handling evidence properly, preserving the integrity of tools and equipment, maintaining the chain of custody, and storing evidence securely.7 Although it may not be feasible to record every event or action taken in response to an incident, having a record of the major events and actions taken helps ensure that nothing has been overlooked, and helps explain to others how the incident was handled.

2.6 Recommendations

The key recommendations on establishing and organizing a forensic capability are as follows:

Organizations should have a capability to perform computer and network forensics.

Organizations should determine which parties should handle each aspect of forensics.

Incident handling teams should have robust forensic capabilities.

Many teams within an organization should participate in forensics.

Forensic considerations should be clearly addressed in policies. At a high level, policies should allow authorized personnel to monitor systems and networks and perform investigations for legitimate reasons under appropriate circumstances.

· Forensic policy should clearly define the roles and responsibilities

· The organization policies, guidelines, and procedures should clearly explain what forensic actions should and should not be performed under normal and special circumstances and should address the use of anti-forensic tools and techniques.

· Incorporating forensic considerations into the information system life cycle can lead to more efficient and effective handling of many incidents.

Coordination Plan

“… one common problem is that many organizations find it resource-intensive to maintain current lists of personnel to contact regarding each different type of incident that may occur.”, Chevalier et at al (2006, p. 31). If any updates are made make every effort to inform all members of the policy update. Make every attempt to ensure a positive mind set and ensure that all are improving their skill set, for instance, making sure all certifications/accreditations are up to date.

Metrics

Blah blah blah

Conclusion

At the end of the day I must be a well “Documented, Actionable and Up-to-date.” plan (Balaouras, 2009, p. 6-7). The concepts and strategies listed will enable your business to have an effective plan for crisis management.

In conclusion, it is imperative to note that several issues can lead to big data loss and related incidences. As such, organizations should ensure that they have a competent response team. The response team should entail professionals such as forensic officers that ensure that the system is carefully analyzed. As well, the team should be facilitated with all the necessary resources to ensure that the response is effective and timely.

References

Proposed Reference Material

National Institute of Technology and Standards = Below

Guide to Computer Forensics & Investigations 5th Edition = Below

Responding to Customer's Security Incidents, Part 1: Establishing Teams and a Policy = Locate

Balaouras, S., Herald, A., Yates, S., (February 26, 2009). Businesses Take BC Planning More Seriously.

Retrieved from https://www.forrester.com/report/Businesses+Take+BC+Planning+More+Seriously/-/E-RES47924

Bowen, P., Gallup, D., Lynes, D., Phillips, A., Swanson, M. (May, 2010). NIST Special Publication 800-34 Rev 1. Contingency Planning Guide for Federal Information Systems. p. 13-149. Retrieved from https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf

Branson, J., Nolan, R., O’Sullivan, C., Waits, C. (Mar, 2005). CERT Training and Education Handbook, Carnegie Mellon. First Responders Guide to Computer Forensics. p.106-113. Retrieved from

https://resources.sei.cmu.edu/asset_files/Handbook/2005_002_001_14429.pdf

Burke, K., Dudley, R., Good, T., Nolan, T., White, G., (Sep 21, 2006). NIST SP 800-84, Guide to Test, Training and Exercise Programs for Information Technology Plans and Capabilities. Retrieved from https://www.nist.gov/publications/guide-test-training-and-exercise-programs-it-plans-and-capabilities

Chevalier, S., Dang, H., Grance, T., Kent, K. (Aug, 2006). NIST Special Publications 800-86. Guide to Integrating Forensic Techniques into Incedent Response pg31Retrieved from https://ws680.nist.gov/publication/get_pdf.cfm?pub_id=50875

MHA Consulting Team (Nov 8, 2016). MHA Consulting. Testing and Training for Business Continuity

or Disaster Recovery. Retrieved from https://www.mha-it.com/2016/11/training-for-business-

continuity/

University of Maryland University College (2018). CSEC 650 9049 Service Restoration and Business Continuity. Module 11. Retrieved from https://learn.umuc.edu/d2l/le/content/310664/viewContent/11661324/View