1 / 5100%
Running Head: ISE 620
1
ISE 620 : Final Project Milestone 1
SNHU
ISE 620
2
1. Detection
Key Steps
• Clear definition of a security incident
• Classification or categorization of the security incident such as Denial of
Service (DoS) attack, Malicious Code attack, etc
Roles and Responsibilities
• The Supervisory department would be responsible to define cyber incident.
The professionals in the department must possess the most updated
technological knowledge in the Finger Lakes Community Bank
• In case any security breach incident takes place, the department would be
responsible to identify the specific type of incident and the data that could be
adversely affected.
Rationale
The simple and understandable definition of a security incident would act as
the foundation to detect any kind of abnormal behavior or anomaly in the IT
ecosystem. By understanding the core features of a security incident, a suitable
action plan could be designed to respond to the situation.
The classification of the incident would help to narrow down what the hacker’s
intentions could be and it would help to understand the exact implications of the
attack. For example, in case a malicious code is running in the organizational
network, it can be narrowed down by identifying whether it is a virus, worm or
something else.
2. Response
ISE 620
3
Key Steps
• Evaluation of the scope, implication, and magnitude of the security incident
• Determining the severity of the security incident (Insignificant< Low<
Medium< High< Extreme) and the criteria that it fits into
• Making an attempt to regain control of the situation by restricting the damage
• After the situation is checked, making a further investigation to identify the
cause of the incident by analyzing the logs of devices
Roles and Responsibilities
• The site team is responsible for ascertaining the level of security of an
incident. The professionals will identify the systems that will be affected by
the incident. Then they can decide the severity of a threat.
• The site team will try to control and manage the situation. These experts will
take the infected systems offline and eradicate the incident by following
suitable recovery protocols. ab ab
• The Supervisory department will carry out further investigations to identify the
root cause of the issue. They will find corrective solutions so that similar
incidents do not take place further
Rationale
Ascertaining the severity of an incident is necessary as it will help to design
the proper course of action. It will help to arrive at the suitable course of action
that can be taken to manage the severity.
Attempting to gain control of the situation will help to restrict the overall
damage so that normal business activities can be continued. This step is necessary as
it can help to identify the exact causes of the security concern.
ISE 620
4
A thorough analysis of the problem will help to ensure that such an incident
does not occur again.
3. Communication and Reporting
Key Steps
• Development of a contact list which captures the contact information of the
individuals who would be managing security-related incidents
• While communicating an incident, it should be made over fax or phone
• Details on incident response process must be documented and shared with
everyone. The incident report must comprise of details on the consequence of
an attack, discovery method, etc. ab
Roles and Responsibilities
• The support team must design the contact list who would be managing the
security incidents. They would be communicating with all members of the
firm.
• Each team must be involved in the incident communication process.
• The supervisory department must maintain records of information on all
security incidences. It would also take care of maintaining the incident report.
Rationale
The contact list would be of paramount importance at the time of a security
incident. It would ensure that management can get in touch with everyone at the
time of need.
ISE 620
5
The proper maintenance of records relating to all information on a security event is
vital as it would act as evidence in the court of law, and it would act as a
reference point to avoid similar incidents in future.
4. Prevention
Key Steps
• Involving in hardening processes by implementing the latest security standards,
disabling redundant services, installing antivirus software, and applying the
firm’s security policies
Roles and Responsibilities
• The supervisory department must come up with the best preventive approaches
such as the selection of effective antivirus software, and the proper encryption
of data so that security incidents could be avoided.
• The site team would be responsible to conduct training on employees so that
they could learn about new security measures and approaches.
Rationale
The involvement of the supervisory department and the site team would be
necessary to ensure that the preventive strategy is implemented in a coordinated
manner. The supervisory department professionals would come up with effective
preventive systems that are based on the prevalent security incident which affected
the firm. The site team would put the preventative measures into action by involving
in software installation and providing training to the organizational personnel.
Students also viewed