Running Head: ISE 620
1
ISE 620 : Final Project Milestone 1
ISE 620
2
1. Detection
Key Steps
• Clear definition of a security incident
• Classification or categorization of the security incident such as Denial of Service
(DoS) attack, Malicious Code attack, etc
Roles and Responsibilities
• The Supervisory department would be responsible to define cyber incident. The
professionals in the department must possess the most updated technological
knowledge in the Finger Lakes Community Bank
• In case any security breach incident takes place, the department would be
responsible to identify the specific type of incident and the data that could be
adversely affected.
Rationale
The simple and understandable definition of a security incident would act as the
foundation to detect any kind of abnormal behavior or anomaly in the IT ecosystem. By
understanding the core features of a security incident, a suitable action plan could be
designed to respond to the situation.
The classification of the incident would help to narrow down what the hacker’s
intentions could be and it would help to understand the exact implications of the attack.
For example, in case a malicious code is running in the organizational network, it can be
narrowed down by identifying whether it is a virus, worm or something else.
2. Response
ISE 620
3
Key Steps
• Evaluation of the scope, implication, and magnitude of the security incident
• Determining the severity of the security incident (Insignificant< Low< Medium<
High< Extreme) and the criteria that it fits into
• Making an attempt to regain control of the situation by restricting the damage
• After the situation is checked, making a further investigation to identify the cause
of the incident by analyzing the logs of devices
Roles and Responsibilities
• The site team is responsible for ascertaining the level of security of an incident.
The professionals will identify the systems that will be affected by the incident.
Then they can decide the severity of a threat.
• The site team will try to control and manage the situation. These experts will take
the infected systems offline and eradicate the incident by following suitable
recovery protocols. g g
• The Supervisory department will carry out further investigations to identify the root
cause of the issue. They will find corrective solutions so that similar incidents do
not take place further
Rationale
Ascertaining the severity of an incident is necessary as it will help to design the
proper course of action. It will help to arrive at the suitable course of action that can be
taken to manage the severity.
Attempting to gain control of the situation will help to restrict the overall damage
so that normal business activities can be continued. This step is necessary as it can help to
identify the exact causes of the security concern.
ISE 620
4
A thorough analysis of the problem will help to ensure that such an incident does not
occur again.
3. Communication and Reporting
Key Steps
• Development of a contact list which captures the contact information of the
individuals who would be managing security-related incidents
• While communicating an incident, it should be made over fax or phone
• Details on incident response process must be documented and shared with
everyone. The incident report must comprise of details on the consequence of an
attack, discovery method, etc. g
Roles and Responsibilities
• The support team must design the contact list who would be managing the security
incidents. They would be communicating with all members of the firm.
• Each team must be involved in the incident communication process.
• The supervisory department must maintain records of information on all security
incidences. It would also take care of maintaining the incident report.
Rationale
The contact list would be of paramount importance at the time of a security
incident. It would ensure that management can get in touch with everyone at the time of
need.
The proper maintenance of records relating to all information on a security event is vital as
it would act as evidence in the court of law, and it would act as a reference point to avoid
similar incidents in future.
ISE 620
5
4. Prevention
Key Steps
• Involving in hardening processes by implementing the latest security standards,
disabling redundant services, installing antivirus software, and applying the firm’s
security policies
Roles and Responsibilities
• The supervisory department must come up with the best preventive approaches
such as the selection of effective antivirus software, and the proper encryption of
data so that security incidents could be avoided.
• The site team would be responsible to conduct training on employees so that they
could learn about new security measures and approaches.
Rationale
The involvement of the supervisory department and the site team would be
necessary to ensure that the preventive strategy is implemented in a coordinated manner.
The supervisory department professionals would come up with effective preventive
systems that are based on the prevalent security incident which affected the firm. The site
team would put the preventative measures into action by involving in software installation
and providing training to the organizational personnel.