Running Head: ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 1
SNHU
ISE 620 Incident Detection and Response
Final Project Submission
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 2
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g Table of Contents
Executive Summary ............................................................................................................................. 3
Overview ............................................................................................................................................ 3
Legal, Regulatory, and Policy Compliance ................................................................................ 4
Operational Plan and Analysis ........................................................................................................ 5
Incident Process Response: Steps, Key Roles and Responsibilities ..................................... 5
Courses of Action Table................................................................................................................ 7
After actions or lessons learned ................................................................................................ 12
Communications plan .................................................................................................................... 12
Countermeasures Analysis ............................................................................................................ 13
Reduced negative impact on Organizational Systems .................................................. 14
Reduced negative impact on Organizational Operations ............................................. 14
Reduced negative impact on Organizational Personnel ............................................... 15
References ............................................................................................................................................ 16
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 3
Executive Summary
Overview
In the digitalized era, Finger Lakes Community Bank has to introduce suitable
security countermeasures in place so that its vulnerability can be minimized in the
unpredictable cyber setting. The incident response plan that has been designed lays
down the steps that the entity needs to follow in the case of a security event. The
section of the plan has been categorized into several phases namely detection,
response, communication and reposting and prevention. For every phase, unique steps
have been highlighted that will help the organization to be prepared to effectively
respond to a security incident. The next section of the report sheds light on the
incident handling steps that must be followed in different attack phases such as
targeting, exploration or reconnaissance, weaponization, exploitation, installation,
command and control, and achievement of the objective. The action table that has
been presented within the proposed security plan will play a vital role to adopt proper
security strategies so that hackers will not get the scope to invade the security system
of the organization. The details that have been captured will basically shed light on
the various kinds of tactics that online hackers and cybercriminals might use in order
to adversely affect the security posture of the bank. Ultimately, a thorough and in-
depth countermeasure assessment has been carried out. It fundamentally showcases how
the countermeasure strategies can play a key role and help to prevent various kinds
of cyberattacks which can adversely affect the quality of security of the bank. Thus,
the incident response plan has been designed so that the security vulnerabilities of the
organization can be minimized and it can safeguard itself from the malicious intentions
of cybercriminals and hackers. The security plan can be operationalized by providing
adequate training to the organizational personnel so that they can identify any kind of
vulnerability in the security system of the firm.
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 4
Legal, Regulatory, and Policy Compliance
Legal and regulatory matters will play a critical role and mold the
organization’s approach to design various elements of the incident response plan such
as the detection process. As the bank deals with highly sensitive and confidential client
and customer information at all times, the detection process would be conducted
quickly. Such a quick detection process would ensure that the attackers would get
limited time to exploit the vulnerability of the business entity. Similarly, all the
regulatory guidelines need to be strictly adhered to so that the most effective plans
and strategies could be in place to identify malicious elements in the organizational
network.
The existing legal and regulatory issues that have been identified in the
specified organizational scenario would have a major influence on its approach to
respond to security incidents. In the bank, a large number of emails have been sent
and received within a short period of time. In order to effectively respond to security
incidents that might cripple the security posture of the bank, the response must be
designed by involving all the key personnel such as the CFO. There is also the need
to regularly review the log files. Such an approach would enable to identify any kind
of suspicious behavior that has been exhibited in the network of the organization.
While responding to security incidents, it is extremely crucial to evaluate the extent
of the security breach or damage. It can help to implement the appropriate security
incident plan. The malicious element must be eliminated from the system so that the
extent of the damage can be restricted as soon as possible. g
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 5
Several methods can be introduced for resolving the gaps relating to the use
of resources or implementation of processes to address the legal, regulatory, and policy
compliance issues. For example, the active involvement of the Chief Finance Officer
(CFO) is necessary while making any fund transfer. The involvement of all the
organizational personnel is of paramount importance so that robust security measures
can be implemented throughout the organizational setting which can strengthen the
security posture. A transparent communication model must be introduced so that the
communication relating to any abnormal or malicious behavior can be carried out in
an efficient and effective manner. These steps can play a vital role to address the
gaps that exist in the organizational setting of Finger Lakes Community Bank.
g g g g g g g g g g g g g g g g g g g g g g g g g g g Operational Plan and Analysis
Incident Process Response: Steps, Key Roles and Responsibilities
Detection
Step
Roles / Responsibility
Rational Behind
Assignment
Clear definition of a
security incident
The Supervisory
department would be
responsible to define
cyber incident. The
professionals in the
department must
possess the most
updated technological
knowledge in the
Finger Lakes
Community Bank
The simple and
understandable definition of a
security incident would act as
the foundation to detect any
kind of abnormal behavior or
anomaly in the IT ecosystem.
By understanding the core
features of a security incident,
a suitable action plan could
be designed to respond to the
situation
Classification or
categorization of the
security incident such as
Denial of Service (DoS)
attack, Malicious Code
attack, etc
In case any security
breach incident takes
place, the department
would be responsible to
identify the specific
type of incident and the
data that could be
adversely affected.
The classification of the
incident would help to
narrow down what the
hacker’s intentions could be
and it would help to
understand the exact
implications of the attack.
For example, in case a
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 6
malicious code is running
in the organizational
network, it can be narrowed
down by identifying
whether it is a virus, worm
or something else.
Response
Step
Role/Responsibility
Rational Behind
Assignment
Evaluation of the
scope, implication, and
magnitude of the
security incident
The site team is
responsible for ascertaining
the level of security of an
incident. The professionals
will identify the systems
that will be affected by the
incident. Then they can
decide the severity of a
threat
Ascertaining the
severity of an incident is
necessary as it will help to
design the proper course of
action. It will help to arrive
at the suitable course of
action that can be taken to
manage the severity.
Determining the
severity of the security
incident (Insignificant<
Low< Medium< High<
Extreme) and the
criteria that it fits into
The site team will try to
control and manage the
situation. These experts
will take the infected
systems offline and
eradicate the incident by
following suitable recovery
protocols
Attempting to gain control of
the situation will help to
restrict the overall damage so
that normal business activities
can be continued. This step is
necessary as it can help to
identify the exact causes of
the security concern
Making an attempt to
regain control of the
situation by restricting
the damage. After the
situation is checked,
making a further
investigation to identify
the cause of the
incident by analyzing
the logs of devices
The Supervisory
department will carry
out further
investigations to
identify the root cause
of the issue. They will
find corrective solutions
so that similar incidents
do not take place
further
A thorough analysis of
the problem will help to
ensure that such an incident
does not occur again.
Communication and Reporting
Steps
Roles/ Responsibility
Rational
Development of a
contact list which
captures the contact
information of the
individuals who would
be managing security-
related incidents
The support team must
design the contact list who
would be managing the
security incidents. They
would be communicating
with all members of the
firm.
The contact list
would be of paramount
importance at the time of a
security incident.
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 7
While communicating
an incident, it should
be made over fax or
phone
Each team must be
involved in the incident
communication process.
It would ensure that
management can get in touch
with everyone at the time of
need.
Details on incident
response process must
be documented and
shared with everyone.
The incident report
must comprise of
details on the
consequence of an
attack, discovery
method, etc. g
The supervisory
department must
maintain records of
information on all
security incidences. It
would also take care of
maintaining the incident
report.
The proper maintenance of
records relating to all
information on a security
event is vital as it would
act as evidence in the court
of law, and it would act as
a reference point to avoid
similar incidents in future.
Prevention
Steps
Roles/ Responsbility
Rational
Involving in hardening
processes by
implementing the latest
security standards,
disabling redundant
services, installing
antivirus software, and
applying the firm’s
security policies
The supervisory
department must come
up with the best
preventive approaches
such as the selection of
effective antivirus
software, and the
proper encryption of
data so that security
incidents could be
avoided. The site team
would be responsible to
conduct training on
employees so that they
could learn about new
security measures and
approaches.
The involvement of
the supervisory department
and the site team would be
necessary to ensure that the
preventive strategy is
implemented in a
coordinated manner. The
supervisory department
professionals would come
up with effective preventive
systems that are based on
the prevalent security
incident which affected the
firm. The site team would
put the preventative
measures into action by
involving in software
installation and providing
training to the
organizational personnel.
Courses of Action Table
No.
Attack
Phase
Attack Action
Compro
mise
indicato
rs
Detection
point
Defensive
countermeasures
Defense
phase
1
Targeting
Identifying a
vulnerable
High
network
traffic
SIEM
platform
reports
Keeping check
of malicious or
Preparation
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 8
device or
system
Continuo
us
traffic
events
involvin
g less
low
transferr
ed data.
Web
server logs
(public
systems)
Perimeter
firewall
logs
suspicious log
addresses
Applying
temporary block
on suspicious
log addresses
Documenting
findings and
action taken
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information
on the
possible
targets
Applying
tools like
Nmap for
scanning
target systems
to identify
open ports or
other
vulnerabilities.
Detectio
n of
external
scans in
traffic
patterns
The rise
in
Social
Engineer
ing
attempts
to
collect
more
informati
on from
personne
l
SIEM
platform or
Intrusion
Detection
and
Prevention
System
(IDPS)
High user
reports
relating to
suspicious
activities
Ensuring SIEM
platform or
Intrusion
Detection and
Prevention
System is
updated
Introducing and
implementing
strict physical
access policies
and practices.
Ensuring
outsiders or
visitors are
allowed to enter
into personnel
premise.
The receptionist
has to make
sure that visitors
do not sneak
into the
“Employee
only” area.
Documentation
of all the
findings and
actions taken by
conducting a
thorough
analysis of the
security
incident.
Identification
3
Weaponizati
on
Downloading,
or installing a
tool which
unifies an
exploit with
malware and
gives rise to
Abnorma
l issues
and
performa
nce-
related
issues
SIEM logs
that have
identified
connections
with
suspicious
Ensuring anti-
virus is updated
Regularly
assessing log
and file history
Documentation
of all the
Identification
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 9
the
deliverable
payload.
Choosing
correct
vulnerabilities
based on the
previous
stage.
Detectio
n of
suspiciou
s files
Logged
connecti
ons with
maliciou
s IP
addresse
s.
IP
addresses
Endpoint
antivirus
warnings
and alerts
findings and
actions taken
after conducting
a thorough
analysis of the
security incident.
4
Exploitation
After the
payload is
established
and deployed
to the
targeted
system, the
built-in
exploit gets
activated to
compromise
the intended
target
The
anti-
virus
detection
of
suspiciou
s files,
especiall
y the
ones
that
have
been
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
of users.
Identific
ation of
maliciou
s or
suspiciou
s files
in
common
locations
.
Logs or
anti-virus
endpoints
detecting
suspicious
files which
are located
on
endpoint
devices. g
SIEM logs
identifying
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to
peculiar or
strange IP
addresses
Employment of
a new and
updated anti-
virus or anti-
malware
platform which
will have the
potential to
capture as well
as quarantine
malicious or
suspicious code
executions.
Offer users and
employees with
proper security
awareness
training. They
need to be
updated about
the latest
security threats
that are
emerging in the
cyber world. g
Introducing a
strict user
access policy so
that they can
carry out their
responsibilities
in an effective
manner.
Documenting
the findings and
actions taken by
conducting a
thorough
Identification
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 10
Detectio
n of
abnormal
behavior
at
endpoint
s
analysis of the
security incident.
5
Installation
Establishment
of a secure
control over
the target
system by
using specific
malware like
Remote
Access
Trojan.
Taking
advantage of
the position
to continue
havening
access into
the system.
Identific
ation of
maliciou
s or
suspiciou
s
processe
s that
are
running
on the
system.
Abnorma
l
behavior
identifie
d at
endpoint
s
Performa
nce
issues
SIEM logs
identifying
connections
with
malicious
IP
addresses
Windows
Event log
highlights
activities
and events
at hours
when the
system
should
have been
idle.
Designing a
deploying a
robust audit
process for
identifying
suspicious or
malicious
processes on the
system.
Making sure
that the
available
Intrusion
Detection and
Prevention
System (IDPS)
updates are
installed on an
on-going basis
on the system.
Hardening the
organization’s
network by
closing all the
ports that are
not needed to
carry out the
legal activities
of the business.
Documenting all
the findings and
actions relating
to the security
incident.
Containment
6
Command
and Control
Building a
communicatio
n network
between the
target system
and the
attacker
Identific
ation of
abnormal
behavior
at the
endpoint
SIEM logs
identifying
connections
with
suspicious
IP
addresses.
Employment of
proxy servers
for varying
kinds of access.
Analysis of logs
Command and
Control to tailor
Containment
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 11
system to
access the
functional
aspects of the
target system.
The ports for
social media
and cloud
applications
work fine as
they have
high
bandwidth
which is
because they
are left open.
This makes it
difficult to
identify
suspicious
activities.
Performa
nce
issues
Running
of
suspiciou
s
processe
s on the
system.
Logs
revealing
a
connecti
on to
maliciou
s IP
addresse
s.
Windows
Event log
shows
activities
at hours
when the
system
should
have been
idle.
Large data
transfers
revealed
by logs
the blocking
mechanism.
Perimeter
firewall logs
show outbound
connections.
Documentation
of all the
findings and
actions taken by
conducting
thorough
analysis of the
security incident.
7
Achieving
the objective
Using proper
controls over
the target
system for
accomplishing
the chief
target
objective.
Creation
of
unauthor
ized
accounts
at the
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnorma
l file
activity
Corrupte
d or
destroye
d data
found
on the
system
Complet
e denial
of
access
to
Abnormal
endpoint
behavior
Windows
Event log
reveals
activities
at hours
when it
should not
be used
SIEM logs
recognizing
malicious
IP
addresses.
Tracing the
mobility of files
that were
copied, moved
or deleted.
Identification of
whether the
compromised
data contained
sensitive
information or
not.
Creating
effective process
relating to
incidence
response.
Documentation
of all the
findings and
actions taken by
conducting a
thorough
analysis of the
security incident.
Eradication
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 12
system
resources
g
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is extremely vital
to maintain the quality of the security infrastructure. After making sure that a proper
remedy is in place, it is necessary for the security professionals to make sure that a
proper documentation approach is followed which captures all the details relating to
the incident. In fact, it would assist to devise suitable policies and practices in the
organizational setting so that similar kinds of security incidents could be avoided in
the future. The existence of proper documentation of the entire event would also help
to critically evaluate the security incident and arrive at the findings which can help
to strengthen the overall effectiveness of the security framework of the business entity
that is highlighted in the Cybersecurity Incident Response Plan.
The comprehensive assessment of the entire security incident can enable the
security professionals to get an in-depth insight into the vulnerabilities that were
exploited. They will be empowered to take robust decisions relating to incidence
response. The documentation of appropriate findings will act as the guideline which
will help the professionals to take suitable measures to prevent similar security breach
incidents.
Communications plan
The careful and accurate documentation of the actions and steps is necessary
as it can assist to devise proper strategies, policies, and protocols or the business
undertaking. In addition to this, it is necessary to effectively articulate and
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 13
communicate about the security incident to the key stakeholders. Their knowledge on
the sensitive subject matter is of paramount importance and this will be possible by
making sure a robust documentation process is in place. g On the basis of the nature
and type of the cybersecurity incident that took place, the involved stakeholders must
be given necessary information that will be relevant for them.
For example, in case a security incident compromises private and sensitive
information, it is necessary to take into consideration legislation and regulations so
that it can identify who are the parties that must be notified about the security
incident. According to the Federal Trade Commission, good communication is
necessary so that the concern and frustration of the customers can be limited to a
certain degree (Data Breach Response: A Guide for Business, 2019). In the
organizational setting, it is necessary to intimate the suitable personnel about the
security breach incident. The information sharing would help to take necessary
measures so that the degree of vulnerability could be contained. As the information
relating to the security incident might have a different degree of relevance for the
involved parties, a thorough documentation would enable the personnel to get a
comprehensive idea about the incident and associated implications.
Countermeasures Analysis
The proper introduction and execution of the countermeasures would help to
effectively curb the online threats and risks. In addition to this, it would also help to
strengthen the existing security policies and practices that are implemented in the
organizational setting. The countermeasures have been designed so that the negative
implication on various elements could be limited such as organizational Systems,
organizational operations, and organizational personnel.
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 14
Reduced negative impact on Organizational Systems
The security analysts are supposed to carefully analyse the activities that are
conducted on the organizational network. Such a countermeasure would play a critical
role to make sure that malicious and suspicious activities or behaviour could be
identified right from the start. This approach would be necessary to make sure that
the gaps that could exist in the Organizational Systems can be identified and suitable
actions can be taken to mitigate the security problem (Antivirus Best Practices, 2019).
The application of necessary security tools such as Nmap would help to
conduct the scanning activities so that the target could be identified and suitable
measures could be taken by the Information Technology department for taking effective
actions so that the organizational system would not get compromised. Similarly, the
use of the most effective anti-virus or anti-malware platform in the business setting
would ensure that the system functions in an efficient and secure manner (Antivirus
Best Practices, 2019).
Reduced negative impact on Organizational Operations
By making sure that all the security tools and applications are effective to deal
with the vulnerabilities and threats, they must be regularly updated. Similarly, the
proper check of the IP addresses that are a part of the network would help to identify
any suspicious or malicious activity that would be evident in the firm’s Information
Technology infrastructure. The proper maintenance of the IP logs would help the
Network Administrators to capture any activities that are not related to the business
activities and processes. Such a holistic approach would be vital to minimizing the
extent of negative impact on the operational activities that are carried out by the
business undertaking.
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 15
The use of the Intrusion Detection and Prevention System (IDPS) would play
a critical role to minimize the adverse impact of the security attack on organizational
operations. These vital tools would primarily help to identify suspicious and malicious
activities that could exist in the IT ecosystem of the business undertaking and
negatively impact the operations and processes.
Reduced negative impact on Organizational Personnel
The effective implementation of physical access controls would make sure that
the security policies and protocols are in place. By restricting the movement of
outsiders or visitors, the organization could ensure that confidential and sensitive
business information would not get leaked to outsiders. By carefully keeping a check
on the movement of employees as well as outsiders in the organizational premises, it
would be easier to introduce suitable security measures and strategies so that the
adverse impact on the organizational personnel could be reduced or completely
mitigated. Addition security cameras and CCTVs could be installed so that the security
personnel could assess the actions of the personnel and identify any kind of abnormal
action or behaviour in the organizational context. In addition to the physical access
policy, a robust user access policy would ensure that unauthorized personnel do not
gain access to confidential business information. The proper documentation of all the
processes would make sure that the personnel of the organization is well informed
about the security actions that should be taken in case a security breach incident takes
place in the future. Such an approach would primarily empower the employees as they
would be prepared to take necessary actions which could minimize the overall
vulnerability of the business undertaking in the uncertain cyber setting.
ISE 620 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 16
References
Antivirus Best Practices. (2019). Retrieved September 27, 2019, from
ncb.mu/English/Documents/Downloads/Reports and Guidelines/Anti Virus Best
Practices.pdf
Data Breach Response: A Guide for Business. (2019). Federal Trade Commission.
Retrieved 23 September 2019, from https://www.ftc.gov/tips-advice/business-
center/guidance/data-breach-response-guide-business