1
SNHU
ISE 510 Security Risk Analysis & Plan
Week 6 HW
Create an CIRT Response Plan for a Typical IT infrastructure
Same as “LAB Manual Create a CIRT Response Plan for a Typical IT Infrastructure”
30 points
2
The figure below is a Mock IT infrastructure of “ASA Schools online” where
they provide learning content to remote students that sign-up over the Internet.
The student workstations can be anywhere in the world, but mostly they are
from the US. You don’t have to be a CISCO Architecture to do this assignment.
The point here that each of the 7-Domains are present (user, workstation, LAN,
WAN-to-WAN, WAN, application, and remote access). These are shown in
Appendix.
Figure 1: Mock IT Infrastructure - Copied from JBL LAB Manual
3
PART I
1. Build a CIRT Plan
a. Purpose
CIRT refers to a computer incident response team that consists of a group involved in the
handling of events of threats related to security breaches of the computer. The purpose of
the CRT plan is to help the different organizations in the identification of probable
computer incidents and in preparation for dealing with the same. The plan will include all
computer incident related policies and the ways of handling them effectively. The CIRT
will enable the creation of a link with the Disaster Recovery Plan (DRP) (Cichonski et al.,
2013). The implementation of the CIRT plan will assist you in applying your critical
thinking to the potential problems related to computer incidents.
b. Roles and Responsibilities of the CIRT Plan.
A key requisite of the CIRT is a team having a group of people with diverse skill sets
from different areas of the organization for ensuring an optimum balance of skills. This
enables the fulfillment of the multiple roles in an organization by the team members.
The different roles that need to be filled up by the CIRT members include:
• Human Resource
• Team Leader
• Communication
• Information Security Members
• Physical Security
• Network Administrators
• Legal
The member of CIRT needs to take charge of the different responsibilities for the
successful development of the plan. The different responsibilities of the CIRT plan are:
• Conduct inquiry of the incident
• Find out the potential cause of the incidents
• Develop effective procedures for incident response
4
• Secure the collected evidence
• Employ the Chain of custody
• Suggest ways or control measures to prevent incidents in future
c. Proposed CIRT Plan:
1) Preparation
The preparation phase involves the designing of the CIRT plan where the computer
incidents will be defined and the plan will be created. The team members of CIRT are
assigned particular roles and responsibilities and are provided with appropriate training to
enable them to execute their part effectively and efficiently (Cichonski et al., 2013). The
employees associated with the CIRT plan are well prepared to help them recognize, contain,
as well as mitigate the arising incidents. The approval and funding of the plan are also
ensured in the preparation stage of the CIRT plan. The use of methods like drill can be
helpful in the evaluation of the effectiveness of the plan. (Davis Ellis)
2) Identification
The identification phase of the CIRT plan is also referred to as the detection and analysis
phase. This phase includes the use of different controls for the detection of probable
incidents. The phase evaluates the events to find out whether the actual events are false or
false positive. The identification phase involves the application of AV software and
intrusion detection systems (IDS).
The important questions that need to be raised by the CIRT group members in this phase
are:
• When did the actual event take place?
• How was the event located?
• By whom was it discovered?
• What are the different areas that are impacted by the event?
• What are the potential scopes of the event?
• How will the event affect the different operations of the organization?
• Has the team been successful in discovering the point of entry of the incident?
(Davis Ellis)
3) Containment
5
After the detection and analysis phase of the CIRT plan, the next phase is containment
where the detected incident is contained. This phase includes the removal of the threat
causing devices from the internet and network connections of the organization. It also
includes the updating of the systems and restoration of the organizational operations with
the help of effective back-up systems. The credentials related to the administration and user
access are changed. The containment of the incident helps in ensuring that the spreading of
the threat is stopped, thus eliminating the chances of more damage to the organization. In
this stage, the CIRT members also review the current policies, passwords, and remote
access protocols for ensuring enhanced authentication.
The questions to be raised by the CIRT in this phase are:
• What has been done by the team for the containment of incidents in the short-term
and long term?
• Has any of the discovered malware been detached from the other networks?
• What are the effective backup systems in the current scenario?
• Does the remote access necessitate true multi-factor authentication?
• Have the team hardened, reviewed, and changed the access credentials? c
• Has the team been successful in implementing the recent patches and updates?
(Davis Ellis)
4) Eradication
The detection of the incident leads to its eradication. In the eradication phase, it is
important to cross-check that all the traces of malware have been removed to ensure the
optimum security of the systems of the organization (Gibson, 2014). The process of
detection and removal continuous until all the malicious elements are cleaned.
The potential questions to be answered during this phase are:
• Has the CIRT group been successful in removing all the malware securely?
• Has all the patches and updates been applied?
• Is the re-imaging of the system possible? (Davis Ellis)
5) Recovery
The recovery phase involves the process of getting back the devices and systems of the
organization to their operational condition. It includes the restoration of the functioning of
the affected systems and eliminating the occurrence of another incident.
6
The questions that should trigger in this phase are:
• When is it possible to return the devices and systems to their original environment?
• What are the possible ways of testing, hardening, and patching the systems?
• Is it possible to trust and restore the system through a backup?
• What effective tools can be used to avoid a particular incident in the future? (Davis
Ellis)
6) Lessons Learned
After the recovery process, an after-review meeting is held to determine the lessons learned.
This phase aims to find out the effective response for the incidents and the possible ways
for improvement. The lessons learned can help in the enhancement of the CIRT plan that
can be documented for future use.
The questions to be answered during this phase are:
• What changes can be made to ensure enhanced security?
• What are the possible ways of training employees differently?
• What were the weaknesses of the organization that led to the incident?
• What are the ways of ensuring that the same incident does not get repeated in the
future? (Davis Ellis)
d. The Incident Response Process
The incident response process begins immediately after the occurrence of an incidence. It
starts with the preparation phase where the security policies are identified, establishes and
recovered. The employees are prepared through proper training and the available tools are
effectively used. Then comes the Identification phase where the actual incident is identified.
It involves the assessment of the affected systems for malicious activities. The Containment
phase includes the containment of the incident. It involves restricting the incident from
spreading more and causing further damage to the organization. The Investigation phase
includes the determination of the ways how and when the incident happened. In this process,
all the policies and processes are reviewed as well as documented properly. The Eradication
phase includes the elimination or cleaning up of the malicious software from the network and
systems. The Recovery phase restores the original functioning of the systems. The Follow-Up
phase involves a discussion regarding the changes to be made in the entire process and
implementation as well as documentation of the same.
7
PART II Answer these questions about CIRT Plans
1. How might ASA Schools know if they were being attacked over the network
or Internet?
The possible ways of knowing about the attack are:
1. Unwanted Toolbars: The emergence of toolbars on the browsers that you do not
know is a potent symbol of attack.
2. Frequent pop-ups are another signal that must not be ignored.
3. Ransom Message: This is a kind of malware that restricts your access to some data
and demand payment for its access. On rebooting, the malware goes away. It can be
restored by making the payment of the ransom or with a backup system.
4. Redirection: Getting continuously redirected to another website during your internet
searches is another signal of a possible attack.
5. Fake Anti-virus software messages: This message attracts users to buy the anti-virus
package and extracts their credit card information.
6. Unexpected Software Installations: In addition to desired software, another software
may be installed without your knowledge.
7. Disablement of Antimalware, registry editor, and task manager is a symbol or
potential attack.
8. The DDoS attack that prevents the effective functioning of services is a common
attack for schools.
9. Using the right online password yet seeing the account not working is an attack
signal.
Automatic moving of mouse and making selections is another attack symbol
2. Inappropriate usage incidents occur when users violate internal policies. Give
two examples of this from our textbook (and page number):
The two examples are:
• the copying of the proprietary data of a secured system to access an insecure system
• Visiting a malicious website which is already identified as off-limits (Gibson, p.
402).
8
3. One of the important steps when handling an incident is to identify the
impact and priority of the incident. How does Gibson (2004) address that?
The rating system can be implemented through the use of a numerical value. The effect
rating definitions stated in Table 15-1 will assist in figuring out the rating and the table
will help in finding the critical level of the attack.
The formula to be used is:
(Current Effect Rating x.25) + (Projected Effect Rating x.25) + (Criticality Rating x.50)
10 x .25 + .50 x .25 + .50 + .50
2.5 + 12.5 + 25
Incident Impact Score = 40
This will be helpful for rating the incident’s impact. The score will range from 0-100. The
minimal value is 0 and critical value is 100.
9
References
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2013). Computer Security Incident
Handling Guide. International Journal of Computer Research, 20(4), 459.
Gibson, D. (2014). Managing risk in information systems. Jones & Bartlett Publishers.
Appendix c - Seven major areas of risk in IT infrastructure
10
From: Jones and Bartlett Learning, TOPIC 1.
Here are the seven major areas of risk in IT infrastructure: (See Image below).
1. USER: The user domain risk areas include user names, passwords, biometric or other
authentication, and social engineering.
2. WORKSTATION: In the workstation domain, the risk areas include end user systems,
laptops, desktops, and cells phones. The “desktop domain” where most users enter the IT
infrastructure
3. LAN: In the local area network (LAN) domain, the risk areas include the equipment
required to create an internal LAN, such as hubs, switches, and media. Small network
organized by function or department, allowing access to all resources on the LANs.
4. LAN-to-WAN: The risk areas in the LAN-to-wide area network (WAN) domain include
the transition area between the LAN and the WAN, including the router and the firewall.
The point at which the IT infrastructure joins a WAN and the Internet
5. WAN: The WAN domain risk areas include the routers and circuits connecting the
WAN. The point at which the WAN connects to other WANs via the Internet
6. APPLICATION: In the system, or application, domain, the risk areas include the
applications you run on your network, such as e-mail, database, and Web applications.
Holds all of the mission-critical systems, applications, and data
7. REMOTE ACCESS: The risk areas in the remote access domain include applications,
such as a virtual private network (VPN) to guide remote or travelling users. Connects
remote employees and partners to the IT infrastructure
11
Seven major areas of risk in IT infrastructure