1 / 18100%
Running Head: ISE 620
1
SNHU
ISE 620 Incident Detection and Response
Final Project Submission
ISE 620
2
ad
Table of Contents
Executive Summary ........................................................................................................................... 3
Overview ............................................................................................................................................ 3
Legal, Regulatory, and Policy Compliance ........................................................................ 4
Operational Plan and Analysis .................................................................................................. 5
Incident Process Response: Steps, Key Roles and Responsibilities ....................... 5
Courses of Action Table.......................................................................................................... 8
After actions or lessons learned ........................................................................................ 13
Communications plan .................................................................................................................. 14
Countermeasures Analysis .......................................................................................................... 15
Reduced negative impact on Organizational Systems ......................................... 15
Reduced negative impact on Organizational Operations .................................... 16
Reduced negative impact on Organizational Personnel ...................................... 17
References ............................................................................................................................................ 18
ISE 620
3
Executive Summary
Overview
In the digitalized era, Finger Lakes Community Bank has to
introduce suitable security countermeasures in place so that its vulnerability
can be minimized in the unpredictable cyber setting. The incident response
plan that has been designed lays down the steps that the entity needs to
follow in the case of a security event. The section of the plan has been
categorized into several phases namely detection, response, communication
and reposting and prevention. For every phase, unique steps have been
highlighted that will help the organization to be prepared to effectively
respond to a security incident. The next section of the report sheds light
on the incident handling steps that must be followed in different attack
phases such as targeting, exploration or reconnaissance, weaponization,
exploitation, installation, command and control, and achievement of the
objective. The action table that has been presented within the proposed
security plan will play a vital role to adopt proper security strategies so
that hackers will not get the scope to invade the security system of the
organization. The details that have been captured will basically shed light
on the various kinds of tactics that online hackers and cybercriminals
might use in order to adversely affect the security posture of the bank.
Ultimately, a thorough and in-depth countermeasure assessment has been
carried out. It fundamentally showcases how the countermeasure strategies
can play a key role and help to prevent various kinds of cyberattacks
which can adversely affect the quality of security of the bank. Thus, the
incident response plan has been designed so that the security vulnerabilities
ISE 620
4
of the organization can be minimized and it can safeguard itself from the
malicious intentions of cybercriminals and hackers. The security plan can be
operationalized by providing adequate training to the organizational personnel
so that they can identify any kind of vulnerability in the security system
of the firm.
Legal, Regulatory, and Policy Compliance
Legal and regulatory matters will play a critical role and mold the
organization’s approach to design various elements of the incident response
plan such as the detection process. As the bank deals with highly
sensitive and confidential client and customer information at all times, the
detection process would be conducted quickly. Such a quick detection
process would ensure that the attackers would get limited time to exploit
the vulnerability of the business entity. Similarly, all the regulatory
guidelines need to be strictly adhered to so that the most effective plans
and strategies could be in place to identify malicious elements in the
organizational network.
The existing legal and regulatory issues that have been identified in
the specified organizational scenario would have a major influence on its
approach to respond to security incidents. In the bank, a large number of
emails have been sent and received within a short period of time. In
order to effectively respond to security incidents that might cripple the
security posture of the bank, the response must be designed by involving
all the key personnel such as the CFO. There is also the need to
ISE 620
5
regularly review the log files. Such an approach would enable to identify
any kind of suspicious behavior that has been exhibited in the network of
the organization. While responding to security incidents, it is extremely
crucial to evaluate the extent of the security breach or damage. It can
help to implement the appropriate security incident plan. The malicious
element must be eliminated from the system so that the extent of the
damage can be restricted as soon as possible.
Several methods can be introduced for resolving the gaps relating to
the use of resources or implementation of processes to address the legal,
regulatory, and policy compliance issues. For example, the active
involvement of the Chief Finance Officer (CFO) is necessary while making
any fund transfer. The involvement of all the organizational personnel is of
paramount importance so that robust security measures can be implemented
throughout the organizational setting which can strengthen the security
posture. A transparent communication model must be introduced so that the
communication relating to any abnormal or malicious behavior can be
carried out in an efficient and effective manner. These steps can play a
vital role to address the gaps that exist in the organizational setting of
Finger Lakes Community Bank.
Operational Plan and Analysis
Incident Process Response: Steps, Key Roles and Responsibilities
Detection
Step
Roles / Responsibility
Rational Behind
Assignment
ISE 620
6
Clear definition of a
security incident
The Supervisory
department would
be responsible to
define cyber
incident. The
professionals in the
department must
possess the most
updated technological
knowledge in the
Finger Lakes
Community Bank
The simple and
understandable definition
of a security incident
would act as the
foundation to detect any
kind of abnormal
behavior or anomaly in
the IT ecosystem. By
understanding the core
features of a security
incident, a suitable action
plan could be designed
to respond to the situation
Classification or
categorization of the
security incident such
as Denial of Service
(DoS) attack, Malicious
Code attack, etc
In case any
security breach
incident takes place,
the department
would be
responsible to
identify the specific
type of incident
and the data that
could be adversely
affected.
The classification of
the incident would help
to narrow down what
the hacker’s intentions
could be and it would
help to understand the
exact implications of
the attack. For example,
in case a malicious
code is running in the
organizational network,
it can be narrowed
down by identifying
whether it is a virus,
worm or something
else.
Response
Step
Role/Responsibility
Rational Behind
Assignment
Evaluation of the
scope, implication,
and magnitude of
the security incident
The site team is
responsible for
ascertaining the level
of security of an
incident. The
professionals will
identify the systems
that will be affected
by the incident. Then
they can decide the
severity of a threat
Ascertaining the
severity of an incident
is necessary as it will
help to design the
proper course of action.
It will help to arrive
at the suitable course
of action that can be
taken to manage the
severity.
Determining the
severity of the
security incident
(Insignificant< Low<
Medium< High<
The site team will try
to control and manage
the situation. These
experts will take the
infected systems offline
Attempting to gain
control of the situation
will help to restrict the
overall damage so that
normal business activities
ISE 620
7
Extreme) and the
criteria that it fits
into
and eradicate the
incident by following
suitable recovery
protocols
can be continued. This
step is necessary as it
can help to identify the
exact causes of the
security concern
Making an attempt
to regain control of
the situation by
restricting the
damage. After the
situation is checked,
making a further
investigation to
identify the cause
of the incident by
analyzing the logs
of devices
The Supervisory
department will
carry out further
investigations to
identify the root
cause of the issue.
They will find
corrective solutions
so that similar
incidents do not
take place further
A thorough analysis
of the problem will
help to ensure that
such an incident does
not occur again.
Communication and Reporting
Steps
Roles/ Responsibility
Rational
Development of a
contact list which
captures the contact
information of the
individuals who
would be managing
security-related
incidents
The support team must
design the contact list
who would be
managing the security
incidents. They would
be communicating with
all members of the
firm.
The contact list
would be of paramount
importance at the time
of a security incident.
While communicating
an incident, it
should be made
over fax or phone
Each team must be
involved in the
incident
communication process.
It would ensure that
management can get in
touch with everyone at
the time of need.
Details on incident
response process
must be documented
and shared with
everyone. The
incident report must
comprise of details
on the consequence
of an attack,
discovery method,
etc.
The supervisory
department must
maintain records of
information on all
security incidences.
It would also take
care of maintaining
the incident report.
The proper maintenance
of records relating to
all information on a
security event is vital
as it would act as
evidence in the court
of law, and it would
act as a reference
point to avoid similar
incidents in future.
Prevention
Steps
Roles/ Responsbility
Rational
Involving in
hardening processes
by implementing the
The supervisory
department must
come up with the
The involvement
of the supervisory
department and the site
ISE 620
8
latest security
standards, disabling
redundant services,
installing antivirus
software, and
applying the firm’s
security policies
best preventive
approaches such as
the selection of
effective antivirus
software, and the
proper encryption of
data so that
security incidents
could be avoided.
The site team
would be
responsible to
conduct training on
employees so that
they could learn
about new security
measures and
approaches.
team would be
necessary to ensure that
the preventive strategy
is implemented in a
coordinated manner. The
supervisory department
professionals would
come up with effective
preventive systems that
are based on the
prevalent security
incident which affected
the firm. The site
team would put the
preventative measures
into action by involving
in software installation
and providing training
to the organizational
personnel.
Courses of Action Table
No.
Attack
Phase
Attack
Action
Compro
mise
indicato
rs
Detection
point
Defense
phase
1
Targeting
Identifying
a
vulnerable
device or
system
High
network
traffic
Continuo
us
traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web
server
logs
(public
systems)
Perimeter
firewall
logs
Preparation
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information
on the
Detectio
n of
external
scans
in
SIEM
platform
or
Intrusion
Detection
Identification
ISE 620
9
possible
targets
Applying
tools like
Nmap for
scanning
target
systems to
identify
open ports
or other
vulnerabilities.
traffic
patterns
The
rise
in
Social
Engineer
ing
attempts
to
collect
more
informati
on
from
personne
l
and
Prevention
System
(IDPS)
High
user
reports
relating
to
suspicious
activities
3
Weaponizati
on
Downloading,
or
installing a
tool which
unifies an
exploit
with
malware
and gives
rise to the
deliverable
payload.
Choosing
correct
Abnorma
l
issues
and
performa
nce-
related
issues
Detectio
n of
suspiciou
s files
Logged
SIEM
logs that
have
identified
connections
with
suspicious
IP
addresses
Endpoint
antivirus
warnings
and alerts
Identification
ISE 620
10
vulnerabilities
based on
the
previous
stage.
connecti
ons
with
maliciou
s IP
addresse
s.
4
Exploitation
After the
payload is
established
and
deployed to
the targeted
system, the
built-in
exploit gets
activated to
compromise
the
intended
target
The
anti-
virus
detection
of
suspiciou
s
files,
especiall
y the
ones
that
have
been
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
of
users.
Identific
ation
of
maliciou
s or
suspiciou
s files
in
common
Logs or
anti-virus
endpoints
detecting
suspicious
files
which
are
located
on
endpoint
devices.
SIEM
logs
identifying
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to
peculiar
or
strange
IP
addresses
Identification
ISE 620
11
locations
.
Detectio
n of
abnormal
behavior
at
endpoint
s
5
Installation
Establishment
of a
secure
control
over the
target
system by
using
specific
malware
like
Remote
Access
Trojan.
Taking
advantage
of the
position to
continue
havening
access into
the system.
Identific
ation
of
maliciou
s or
suspiciou
s
processe
s that
are
running
on
the
system.
Abnorma
l
behavior
identifie
d at
endpoint
s
Performa
nce
issues
SIEM
logs
identifying
connections
with
malicious
IP
addresses
Windows
Event
log
highlights
activities
and
events at
hours
when
the
system
should
have
been
idle.
Containment
ISE 620
12
6
Command
and Control
Building a
communicatio
n network
between
the target
system and
the attacker
system to
access the
functional
aspects of
the target
system.
The ports
for social
media and
cloud
applications
work fine
as they
have high
bandwidth
which is
because
they are
left open.
This makes
it difficult
to identify
suspicious
activities.
Identific
ation
of
abnormal
behavior
at
the
endpoint
Performa
nce
issues
Running
of
suspiciou
s
processe
s on
the
system.
Logs
revealing
a
connecti
on to
maliciou
s IP
addresse
s.
SIEM
logs
identifying
connections
with
suspicious
IP
addresses.
Windows
Event
log
shows
activities
at hours
when
the
system
should
have
been
idle.
Large
data
transfers
revealed
by logs
Containment
7
Achieving
the
objective
Using
proper
controls
over the
target
system for
accomplishing
the chief
target
objective.
Creation
of
unauthor
ized
accounts
at
the
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnormal
endpoint
behavior
Windows
Event
log
reveals
activities
at hours
when it
should
not be
used
SIEM
logs
Eradication
ISE 620
13
Abnorma
l file
activity
Corrupte
d or
destroye
d data
found
on
the
system
Complet
e
denial
of
access
to
system
resources
recognizing
malicious
IP
addresses.
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is
extremely vital to maintain the quality of the security infrastructure. After
making sure that a proper remedy is in place, it is necessary for the
security professionals to make sure that a proper documentation approach is
followed which captures all the details relating to the incident. In fact, it
would assist to devise suitable policies and practices in the organizational
setting so that similar kinds of security incidents could be avoided in the
future. The existence of proper documentation of the entire event would
also help to critically evaluate the security incident and arrive at the
findings which can help to strengthen the overall effectiveness of the
security framework of the business entity that is highlighted in the
Cybersecurity Incident Response Plan.
ISE 620
14
The comprehensive assessment of the entire security incident can
enable the security professionals to get an in-depth insight into the
vulnerabilities that were exploited. They will be empowered to take robust
decisions relating to incidence response. The documentation of appropriate
findings will act as the guideline which will help the professionals to take
suitable measures to prevent similar security breach incidents.
Communications plan
The careful and accurate documentation of the actions and steps is
necessary as it can assist to devise proper strategies, policies, and
protocols or the business undertaking. In addition to this, it is necessary
to effectively articulate and communicate about the security incident to the
key stakeholders. Their knowledge on the sensitive subject matter is of
paramount importance and this will be possible by making sure a robust
documentation process is in place. On the basis of the nature and type
of the cybersecurity incident that took place, the involved stakeholders must
be given necessary information that will be relevant for them.
For example, in case a security incident compromises private and
sensitive information, it is necessary to take into consideration legislation
and regulations so that it can identify who are the parties that must be
notified about the security incident. According to the Federal Trade
Commission, good communication is necessary so that the concern and
frustration of the customers can be limited to a certain degree (Data
Breach Response: A Guide for Business, 2019). In the organizational
ISE 620
15
setting, it is necessary to intimate the suitable personnel about the security
breach incident. The information sharing would help to take necessary
measures so that the degree of vulnerability could be contained. As the
information relating to the security incident might have a different degree
of relevance for the involved parties, a thorough documentation would
enable the personnel to get a comprehensive idea about the incident and
associated implications.
Countermeasures Analysis
The proper introduction and execution of the countermeasures would
help to effectively curb the online threats and risks. In addition to this,
it would also help to strengthen the existing security policies and practices
that are implemented in the organizational setting. The countermeasures
have been designed so that the negative implication on various elements
could be limited such as organizational Systems, organizational operations,
and organizational personnel.
Reduced negative impact on Organizational Systems
The security analysts are supposed to carefully analyse the activities
that are conducted on the organizational network. Such a countermeasure
would play a critical role to make sure that malicious and suspicious
activities or behaviour could be identified right from the start. This
approach would be necessary to make sure that the gaps that could exist
in the Organizational Systems can be identified and suitable actions can be
taken to mitigate the security problem (Antivirus Best Practices, 2019).
ISE 620
16
The application of necessary security tools such as Nmap would help
to conduct the scanning activities so that the target could be identified
and suitable measures could be taken by the Information Technology
department for taking effective actions so that the organizational system
would not get compromised. Similarly, the use of the most effective anti-
virus or anti-malware platform in the business setting would ensure that
the system functions in an efficient and secure manner (Antivirus Best
Practices, 2019).
Reduced negative impact on Organizational Operations
By making sure that all the security tools and applications are
effective to deal with the vulnerabilities and threats, they must be regularly
updated. Similarly, the proper check of the IP addresses that are a part
of the network would help to identify any suspicious or malicious activity
that would be evident in the firm’s Information Technology infrastructure.
The proper maintenance of the IP logs would help the Network
Administrators to capture any activities that are not related to the business
activities and processes. Such a holistic approach would be vital to
minimizing the extent of negative impact on the operational activities that
are carried out by the business undertaking.
The use of the Intrusion Detection and Prevention System (IDPS)
would play a critical role to minimize the adverse impact of the security
attack on organizational operations. These vital tools would primarily help
to identify suspicious and malicious activities that could exist in the IT
ISE 620
17
ecosystem of the business undertaking and negatively impact the operations
and processes.
Reduced negative impact on Organizational Personnel
The effective implementation of physical access controls would make
sure that the security policies and protocols are in place. By restricting
the movement of outsiders or visitors, the organization could ensure that
confidential and sensitive business information would not get leaked to
outsiders. By carefully keeping a check on the movement of employees as
well as outsiders in the organizational premises, it would be easier to
introduce suitable security measures and strategies so that the adverse
impact on the organizational personnel could be reduced or completely
mitigated. Addition security cameras and CCTVs could be installed so that
the security personnel could assess the actions of the personnel and
identify any kind of abnormal action or behaviour in the organizational
context. In addition to the physical access policy, a robust user access
policy would ensure that unauthorized personnel do not gain access to
confidential business information. The proper documentation of all the
processes would make sure that the personnel of the organization is well
informed about the security actions that should be taken in case a
security breach incident takes place in the future. Such an approach would
primarily empower the employees as they would be prepared to take
necessary actions which could minimize the overall vulnerability of the
business undertaking in the uncertain cyber setting.
ISE 620
18
References
Antivirus Best Practices. (2019). Retrieved September 27, 2019, from
ncb.mu/English/Documents/Downloads/Reports and Guidelines/Anti Virus
Best Practices.pdf
Data Breach Response: A Guide for Business. (2019). Federal Trade
Commission. Retrieved 23 September 2019, from https://www.ftc.gov/tips-
advice/business-center/guidance/data-breach-response-guide-business
Students also viewed