1 / 15100%
Running Head: ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
SNHU
ISE 620 Incident Detection and Response
Final Project Submission
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e Table of Contents
Executive Summary ............................................................................................................................. 3
Overview ............................................................................................................................................ 3
Legal, Regulatory, and Policy Compliance .................................................................................. 4
Operational Plan and Analysis .......................................................................................................... 5
Incident Process Response: Steps, Key Roles and Responsibilities ......................................... 5
Courses of Action Table ................................................................................................................. 7
After actions or lessons learned .................................................................................................. 11
Communications plan .................................................................................................................... 12
Countermeasures Analysis ............................................................................................................ 13
Reduced negative impact on Organizational Systems ..................................................... 13
Reduced negative impact on Organizational Operations ................................................ 14
Reduced negative impact on Organizational Personnel .................................................. 14
References ............................................................................................................................................ 15
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
Executive Summary
Overview
In the digitalized era, Finger Lakes Community Bank has to introduce suitable
security countermeasures in place so that its vulnerability can be minimized in the
unpredictable cyber setting. The incident response plan that has been designed lays down
the steps that the entity needs to follow in the case of a security event. The section of
the plan has been categorized into several phases namely detection, response,
communication and reposting and prevention. For every phase, unique steps have been
highlighted that will help the organization to be prepared to effectively respond to a
security incident. The next section of the report sheds light on the incident handling steps
that must be followed in different attack phases such as targeting, exploration or
reconnaissance, weaponization, exploitation, installation, command and control, and
achievement of the objective. The action table that has been presented within the proposed
security plan will play a vital role to adopt proper security strategies so that hackers will
not get the scope to invade the security system of the organization. The details that have
been captured will basically shed light on the various kinds of tactics that online hackers
and cybercriminals might use in order to adversely affect the security posture of the bank.
Ultimately, a thorough and in-depth countermeasure assessment has been carried out. It
fundamentally showcases how the countermeasure strategies can play a key role and help
to prevent various kinds of cyberattacks which can adversely affect the quality of security
of the bank. Thus, the incident response plan has been designed so that the security
vulnerabilities of the organization can be minimized and it can safeguard itself from the
malicious intentions of cybercriminals and hackers. The security plan can be
operationalized by providing adequate training to the organizational personnel so that they
can identify any kind of vulnerability in the security system of the firm.
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
Legal, Regulatory, and Policy Compliance
Legal and regulatory matters will play a critical role and mold the organization’s
approach to design various elements of the incident response plan such as the detection
process. As the bank deals with highly sensitive and confidential client and customer
information at all times, the detection process would be conducted quickly. Such a quick
detection process would ensure that the attackers would get limited time to exploit the
vulnerability of the business entity. Similarly, all the regulatory guidelines need to be
strictly adhered to so that the most effective plans and strategies could be in place to
identify malicious elements in the organizational network.
The existing legal and regulatory issues that have been identified in the specified
organizational scenario would have a major influence on its approach to respond to
security incidents. In the bank, a large number of emails have been sent and received
within a short period of time. In order to effectively respond to security incidents that
might cripple the security posture of the bank, the response must be designed by
involving all the key personnel such as the CFO. There is also the need to regularly
review the log files. Such an approach would enable to identify any kind of suspicious
behavior that has been exhibited in the network of the organization. While responding to
security incidents, it is extremely crucial to evaluate the extent of the security breach or
damage. It can help to implement the appropriate security incident plan. The malicious
element must be eliminated from the system so that the extent of the damage can be
restricted as soon as possible. e
Several methods can be introduced for resolving the gaps relating to the use of
resources or implementation of processes to address the legal, regulatory, and policy
compliance issues. For example, the active involvement of the Chief Finance Officer
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
(CFO) is necessary while making any fund transfer. The involvement of all the
organizational personnel is of paramount importance so that robust security measures can
be implemented throughout the organizational setting which can strengthen the security
posture. A transparent communication model must be introduced so that the
communication relating to any abnormal or malicious behavior can be carried out in an
efficient and effective manner. These steps can play a vital role to address the gaps that
exist in the organizational setting of Finger Lakes Community Bank.
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e Operational Plan and Analysis
Incident Process Response: Steps, Key Roles and Responsibilities
Detection
Step
Roles / Responsibility
Rational Behind
Assignment
Clear definition of a
security incident
The Supervisory
department would be
responsible to define
cyber incident. The
professionals in the
department must possess
the most updated
technological knowledge
in the Finger Lakes
Community Bank
The simple and understandable
definition of a security incident
would act as the foundation to
detect any kind of abnormal
behavior or anomaly in the IT
ecosystem. By understanding
the core features of a security
incident, a suitable action plan
could be designed to respond
to the situation
Classification or
categorization of the
security incident such as
Denial of Service (DoS)
attack, Malicious Code
attack, etc
In case any security
breach incident takes
place, the department
would be responsible to
identify the specific type
of incident and the data
that could be adversely
affected.
The classification of the
incident would help to
narrow down what the
hacker’s intentions could be
and it would help to
understand the exact
implications of the attack.
For example, in case a
malicious code is running in
the organizational network, it
can be narrowed down by
identifying whether it is a
virus, worm or something
else.
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
Response
Step
Role/Responsibility
Rational Behind
Assignment
Evaluation of the scope,
implication, and
magnitude of the
security incident
The site team is responsible
for ascertaining the level of
security of an incident. The
professionals will identify
the systems that will be
affected by the incident.
Then they can decide the
severity of a threat
Ascertaining the
severity of an incident is
necessary as it will help to
design the proper course of
action. It will help to arrive
at the suitable course of
action that can be taken to
manage the severity.
Determining the severity
of the security incident
(Insignificant< Low<
Medium< High<
Extreme) and the criteria
that it fits into
The site team will try to
control and manage the
situation. These experts will
take the infected systems
offline and eradicate the
incident by following
suitable recovery protocols
Attempting to gain control of
the situation will help to
restrict the overall damage so
that normal business activities
can be continued. This step is
necessary as it can help to
identify the exact causes of the
security concern
Making an attempt to
regain control of the
situation by restricting
the damage. After the
situation is checked,
making a further
investigation to identify
the cause of the incident
by analyzing the logs of
devices
The Supervisory
department will carry
out further investigations
to identify the root
cause of the issue. They
will find corrective
solutions so that similar
incidents do not take
place further
A thorough analysis of
the problem will help to
ensure that such an incident
does not occur again.
Communication and Reporting
Steps
Roles/ Responsibility
Rational
Development of a
contact list which
captures the contact
information of the
individuals who would
be managing security-
related incidents
The support team must
design the contact list who
would be managing the
security incidents. They
would be communicating
with all members of the
firm.
The contact list
would be of paramount
importance at the time of a
security incident.
While communicating
an incident, it should be
made over fax or phone
Each team must be
involved in the incident
communication process.
It would ensure that
management can get in touch
with everyone at the time of
need.
Details on incident
response process must
be documented and
shared with everyone.
The incident report must
comprise of details on
The supervisory
department must
maintain records of
information on all
security incidences. It
would also take care of
The proper maintenance of
records relating to all
information on a security
event is vital as it would act
as evidence in the court of
law, and it would act as a
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 7
the consequence of an
attack, discovery
method, etc. e
maintaining the incident
report.
reference point to avoid
similar incidents in future.
Prevention
Steps
Roles/ Responsbility
Rational
Involving in hardening
processes by
implementing the latest
security standards,
disabling redundant
services, installing
antivirus software, and
applying the firm’s
security policies
The supervisory
department must come
up with the best
preventive approaches
such as the selection of
effective antivirus
software, and the proper
encryption of data so
that security incidents
could be avoided. The
site team would be
responsible to conduct
training on employees
so that they could learn
about new security
measures and
approaches.
The involvement of
the supervisory department
and the site team would be
necessary to ensure that the
preventive strategy is
implemented in a
coordinated manner. The
supervisory department
professionals would come up
with effective preventive
systems that are based on
the prevalent security
incident which affected the
firm. The site team would
put the preventative
measures into action by
involving in software
installation and providing
training to the organizational
personnel.
Courses of Action Table
No.
Attack
Phase
Attack Action
Compro
mise
indicato
rs
Detection
point
Defense
phase
1
Targeting
Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us
traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web server
logs
(public
systems)
Perimeter
firewall
logs
Preparation
2
Exploration
or
Collecting
maximum
Detectio
n of
SIEM
platform or
Identification
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 8
Reconnaissa
nce
information
on the
possible
targets
Applying
tools like
Nmap for
scanning
target systems
to identify
open ports or
other
vulnerabilities.
external
scans in
traffic
patterns
The rise
in
Social
Engineer
ing
attempts
to
collect
more
informati
on from
personne
l
Intrusion
Detection
and
Prevention
System
(IDPS)
High user
reports
relating to
suspicious
activities
3
Weaponizati
on
Downloading,
or installing a
tool which
unifies an
exploit with
malware and
gives rise to
the
deliverable
payload.
Choosing
correct
vulnerabilities
based on the
previous
stage.
Abnorma
l issues
and
performa
nce-
related
issues
Detectio
n of
suspiciou
s files
Logged
connecti
ons with
maliciou
s IP
addresse
s.
SIEM logs
that have
identified
connections
with
suspicious
IP
addresses
Endpoint
antivirus
warnings
and alerts
Identification
4
Exploitation
After the
payload is
The anti-
virus
Logs or
anti-virus
Identification
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 9
established
and deployed
to the targeted
system, the
built-in
exploit gets
activated to
compromise
the intended
target
detection
of
suspiciou
s files,
especiall
y the
ones
that
have
been
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
of users.
Identific
ation of
maliciou
s or
suspiciou
s files in
common
locations
.
Detectio
n of
abnormal
behavior
at
endpoint
s
endpoints
detecting
suspicious
files which
are located
on
endpoint
devices. e
SIEM logs
identifying
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to peculiar
or strange
IP
addresses
5
Installation
Establishment
of a secure
control over
the target
system by
using specific
malware like
Identific
ation of
maliciou
s or
suspiciou
s
processe
SIEM logs
identifying
connections
with
malicious
IP
addresses
Containment
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 10
Remote
Access
Trojan.
Taking
advantage of
the position to
continue
havening
access into
the system.
s that
are
running
on the
system.
Abnorma
l
behavior
identifie
d at
endpoint
s
Performa
nce
issues
Windows
Event log
highlights
activities
and events
at hours
when the
system
should
have been
idle.
6
Command
and Control
Building a
communicatio
n network
between the
target system
and the
attacker
system to
access the
functional
aspects of the
target system.
The ports for
social media
and cloud
applications
work fine as
they have
high
bandwidth
which is
because they
are left open.
Identific
ation of
abnormal
behavior
at the
endpoint
Performa
nce
issues
Running
of
suspiciou
s
processe
s on the
system.
Logs
revealing
a
connecti
on to
maliciou
SIEM logs
identifying
connections
with
suspicious
IP
addresses.
Windows
Event log
shows
activities at
hours when
the system
should
have been
idle.
Large data
transfers
revealed by
logs
Containment
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 11
This makes it
difficult to
identify
suspicious
activities.
s IP
addresse
s.
7
Achieving
the objective
Using proper
controls over
the target
system for
accomplishing
the chief
target
objective.
Creation
of
unauthor
ized
accounts
at the
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnorma
l file
activity
Corrupte
d or
destroye
d data
found
on the
system
Complet
e denial
of
access
to
system
resources
e
Abnormal
endpoint
behavior
Windows
Event log
reveals
activities at
hours when
it should
not be used
SIEM logs
recognizing
malicious
IP
addresses.
Eradication
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is extremely vital to
maintain the quality of the security infrastructure. After making sure that a proper remedy
is in place, it is necessary for the security professionals to make sure that a proper
documentation approach is followed which captures all the details relating to the incident.
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 12
In fact, it would assist to devise suitable policies and practices in the organizational
setting so that similar kinds of security incidents could be avoided in the future. The
existence of proper documentation of the entire event would also help to critically
evaluate the security incident and arrive at the findings which can help to strengthen the
overall effectiveness of the security framework of the business entity that is highlighted
in the Cybersecurity Incident Response Plan.
The comprehensive assessment of the entire security incident can enable the
security professionals to get an in-depth insight into the vulnerabilities that were
exploited. They will be empowered to take robust decisions relating to incidence response.
The documentation of appropriate findings will act as the guideline which will help the
professionals to take suitable measures to prevent similar security breach incidents.
Communications plan
The careful and accurate documentation of the actions and steps is necessary as it
can assist to devise proper strategies, policies, and protocols or the business undertaking.
In addition to this, it is necessary to effectively articulate and communicate about the
security incident to the key stakeholders. Their knowledge on the sensitive subject matter
is of paramount importance and this will be possible by making sure a robust
documentation process is in place. On the basis of the nature and type of the
cybersecurity incident that took place, the involved stakeholders must be given necessary
information that will be relevant for them.
For example, in case a security incident compromises private and sensitive
information, it is necessary to take into consideration legislation and regulations so that it
can identify who are the parties that must be notified about the security incident.
According to the Federal Trade Commission, good communication is necessary so that the
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 13
concern and frustration of the customers can be limited to a certain degree (Data Breach
Response: A Guide for Business, 2019). In the organizational setting, it is necessary to
intimate the suitable personnel about the security breach incident. The information sharing
would help to take necessary measures so that the degree of vulnerability could be
contained. As the information relating to the security incident might have a different
degree of relevance for the involved parties, a thorough documentation would enable the
personnel to get a comprehensive idea about the incident and associated implications.
Countermeasures Analysis
The proper introduction and execution of the countermeasures would help to
effectively curb the online threats and risks. In addition to this, it would also help to
strengthen the existing security policies and practices that are implemented in the
organizational setting. The countermeasures have been designed so that the negative
implication on various elements could be limited such as organizational Systems,
organizational operations, and organizational personnel.
Reduced negative impact on Organizational Systems
The security analysts are supposed to carefully analyse the activities that are
conducted on the organizational network. Such a countermeasure would play a critical
role to make sure that malicious and suspicious activities or behaviour could be identified
right from the start. This approach would be necessary to make sure that the gaps that
could exist in the Organizational Systems can be identified and suitable actions can be
taken to mitigate the security problem (Antivirus Best Practices, 2019).
The application of necessary security tools such as Nmap would help to conduct
the scanning activities so that the target could be identified and suitable measures could
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 14
be taken by the Information Technology department for taking effective actions so that
the organizational system would not get compromised. Similarly, the use of the most
effective anti-virus or anti-malware platform in the business setting would ensure that the
system functions in an efficient and secure manner (Antivirus Best Practices, 2019).
Reduced negative impact on Organizational Operations
By making sure that all the security tools and applications are effective to deal
with the vulnerabilities and threats, they must be regularly updated. Similarly, the proper
check of the IP addresses that are a part of the network would help to identify any
suspicious or malicious activity that would be evident in the firm’s Information
Technology infrastructure. The proper maintenance of the IP logs would help the Network
Administrators to capture any activities that are not related to the business activities and
processes. e Such a holistic approach would be vital to minimizing the extent of negative
impact on the operational activities that are carried out by the business undertaking.
The use of the Intrusion Detection and Prevention System (IDPS) would play a
critical role to minimize the adverse impact of the security attack on organizational
operations. These vital tools would primarily help to identify suspicious and malicious
activities that could exist in the IT ecosystem of the business undertaking and negatively
impact the operations and processes.
Reduced negative impact on Organizational Personnel
The effective implementation of physical access controls would make sure that the
security policies and protocols are in place. By restricting the movement of outsiders or
visitors, the organization could ensure that confidential and sensitive business information
would not get leaked to outsiders. By carefully keeping a check on the movement of
employees as well as outsiders in the organizational premises, it would be easier to
ISE 620 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 15
introduce suitable security measures and strategies so that the adverse impact on the
organizational personnel could be reduced or completely mitigated. Addition security
cameras and CCTVs could be installed so that the security personnel could assess the
actions of the personnel and identify any kind of abnormal action or behaviour in the
organizational context. In addition to the physical access policy, a robust user access
policy would ensure that unauthorized personnel do not gain access to confidential
business information. The proper documentation of all the processes would make sure that
the personnel of the organization is well informed about the security actions that should
be taken in case a security breach incident takes place in the future. Such an approach
would primarily empower the employees as they would be prepared to take necessary
actions which could minimize the overall vulnerability of the business undertaking in the
uncertain cyber setting.
References
Antivirus Best Practices. (2019). Retrieved September 27, 2019, from
ncb.mu/English/Documents/Downloads/Reports and Guidelines/Anti Virus Best
Practices.pdf
Data Breach Response: A Guide for Business. (2019). Federal Trade Commission.
Retrieved 23 September 2019, from https://www.ftc.gov/tips-advice/business-
center/guidance/data-breach-response-guide-business
Students also viewed