Running Head: ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
SNHU
ISE 620 Incident Detection and Response
Final Project Submission
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 2
f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f Table of Contents
Executive Summary .............................................................................................................................. 3
Overview ............................................................................................................................................ 3
Legal, Regulatory, and Policy Compliance .................................................................................... 4
Operational Plan and Analysis ............................................................................................................ 5
Incident Process Response: Steps, Key Roles and Responsibilities.............................................. 5
Courses of Action Table ................................................................................................................... 7
After actions or lessons learned ..................................................................................................... 11
Communications plan ..................................................................................................................... 12
Countermeasures Analysis ............................................................................................................. 13
Reduced negative impact on Organizational Systems ........................................................ 13
Reduced negative impact on Organizational Operations ................................................... 13
Reduced negative impact on Organizational Personnel ..................................................... 14
References ............................................................................................................................................ 15
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 3
Executive Summary
Overview
In the digitalized era, Finger Lakes Community Bank has to introduce suitable security
countermeasures in place so that its vulnerability can be minimized in the unpredictable cyber
setting. The incident response plan that has been designed lays down the steps that the entity
needs to follow in the case of a security event. The section of the plan has been categorized
into several phases namely detection, response, communication and reposting and prevention.
For every phase, unique steps have been highlighted that will help the organization to be
prepared to effectively respond to a security incident. The next section of the report sheds light
on the incident handling steps that must be followed in different attack phases such as
targeting, exploration or reconnaissance, weaponization, exploitation, installation, command
and control, and achievement of the objective. The action table that has been presented within
the proposed security plan will play a vital role to adopt proper security strategies so that
hackers will not get the scope to invade the security system of the organization. The details
that have been captured will basically shed light on the various kinds of tactics that online
hackers and cybercriminals might use in order to adversely affect the security posture of the
bank. Ultimately, a thorough and in-depth countermeasure assessment has been carried out. It
fundamentally showcases how the countermeasure strategies can play a key role and help to
prevent various kinds of cyberattacks which can adversely affect the quality of security of the
bank. Thus, the incident response plan has been designed so that the security vulnerabilities of
the organization can be minimized and it can safeguard itself from the malicious intentions of
cybercriminals and hackers. The security plan can be operationalized by providing adequate
training to the organizational personnel so that they can identify any kind of vulnerability in
the security system of the firm.
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 4
Legal, Regulatory, and Policy Compliance
Legal and regulatory matters will play a critical role and mold the organization’s
approach to design various elements of the incident response plan such as the detection
process. As the bank deals with highly sensitive and confidential client and customer
information at all times, the detection process would be conducted quickly. Such a quick
detection process would ensure that the attackers would get limited time to exploit the
vulnerability of the business entity. Similarly, all the regulatory guidelines need to be strictly
adhered to so that the most effective plans and strategies could be in place to identify
malicious elements in the organizational network.
The existing legal and regulatory issues that have been identified in the specified
organizational scenario would have a major influence on its approach to respond to security
incidents. In the bank, a large number of emails have been sent and received within a short
period of time. In order to effectively respond to security incidents that might cripple the
security posture of the bank, the response must be designed by involving all the key personnel
such as the CFO. There is also the need to regularly review the log files. Such an approach
would enable to identify any kind of suspicious behavior that has been exhibited in the
network of the organization. While responding to security incidents, it is extremely crucial to
evaluate the extent of the security breach or damage. It can help to implement the appropriate
security incident plan. The malicious element must be eliminated from the system so that the
extent of the damage can be restricted as soon as possible. f
Several methods can be introduced for resolving the gaps relating to the use of
resources or implementation of processes to address the legal, regulatory, and policy
compliance issues. For example, the active involvement of the Chief Finance Officer (CFO) is
necessary while making any fund transfer. The involvement of all the organizational
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 5
personnel is of paramount importance so that robust security measures can be implemented
throughout the organizational setting which can strengthen the security posture. A transparent
communication model must be introduced so that the communication relating to any abnormal
or malicious behavior can be carried out in an efficient and effective manner. These steps can
play a vital role to address the gaps that exist in the organizational setting of Finger Lakes
Community Bank.
f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f Operational Plan and Analysis
Incident Process Response: Steps, Key Roles and Responsibilities
Detection
Step
Roles / Responsibility
Rational Behind Assignment
Clear definition of a security
incident
The Supervisory
department would be
responsible to define
cyber incident. The
professionals in the
department must possess
the most updated
technological knowledge
in the Finger Lakes
Community Bank
The simple and understandable
definition of a security incident
would act as the foundation to
detect any kind of abnormal
behavior or anomaly in the IT
ecosystem. By understanding
the core features of a security
incident, a suitable action plan
could be designed to respond to
the situation
Classification or
categorization of the security
incident such as Denial of
Service (DoS) attack,
Malicious Code attack, etc
In case any security
breach incident takes
place, the department
would be responsible to
identify the specific type
of incident and the data
that could be adversely
affected.
The classification of the
incident would help to narrow
down what the hacker’s
intentions could be and it
would help to understand the
exact implications of the
attack. For example, in case a
malicious code is running in
the organizational network, it
can be narrowed down by
identifying whether it is a
virus, worm or something
else.
Response
Step
Role/Responsibility
Rational Behind Assignment
Evaluation of the scope,
implication, and
The site team is responsible
for ascertaining the level of
Ascertaining the
severity of an incident is
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 6
magnitude of the security
incident
security of an incident. The
professionals will identify
the systems that will be
affected by the incident.
Then they can decide the
severity of a threat
necessary as it will help to
design the proper course of
action. It will help to arrive at
the suitable course of action
that can be taken to manage
the severity.
Determining the severity
of the security incident
(Insignificant< Low<
Medium< High<
Extreme) and the criteria
that it fits into
The site team will try to
control and manage the
situation. These experts will
take the infected systems
offline and eradicate the
incident by following
suitable recovery protocols
Attempting to gain control of the
situation will help to restrict the
overall damage so that normal
business activities can be
continued. This step is necessary
as it can help to identify the
exact causes of the security
concern
Making an attempt to
regain control of the
situation by restricting
the damage. After the
situation is checked,
making a further
investigation to identify
the cause of the incident
by analyzing the logs of
devices
The Supervisory
department will carry out
further investigations to
identify the root cause of
the issue. They will find
corrective solutions so
that similar incidents do
not take place further
A thorough analysis of the
problem will help to ensure
that such an incident does not
occur again.
Communication and Reporting
Steps
Roles/ Responsibility
Rational
Development of a contact
list which captures the
contact information of
the individuals who
would be managing
security-related incidents
The support team must
design the contact list who
would be managing the
security incidents. They
would be communicating
with all members of the firm.
The contact list would
be of paramount importance
at the time of a security
incident.
While communicating an
incident, it should be
made over fax or phone
Each team must be
involved in the incident
communication process.
It would ensure that
management can get in touch
with everyone at the time of
need.
Details on incident
response process must be
documented and shared
with everyone. The
incident report must
comprise of details on the
consequence of an attack,
discovery method, etc. f
The supervisory
department must
maintain records of
information on all
security incidences. It
would also take care of
maintaining the incident
report.
The proper maintenance of
records relating to all
information on a security
event is vital as it would act as
evidence in the court of law,
and it would act as a reference
point to avoid similar
incidents in future.
Prevention
Steps
Roles/ Responsbility
Rational
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 7
Involving in hardening
processes by
implementing the latest
security standards,
disabling redundant
services, installing
antivirus software, and
applying the firm’s
security policies
The supervisory
department must come up
with the best preventive
approaches such as the
selection of effective
antivirus software, and
the proper encryption of
data so that security
incidents could be
avoided. The site team
would be responsible to
conduct training on
employees so that they
could learn about new
security measures and
approaches.
The involvement of
the supervisory department
and the site team would be
necessary to ensure that the
preventive strategy is
implemented in a coordinated
manner. The supervisory
department professionals
would come up with effective
preventive systems that are
based on the prevalent
security incident which
affected the firm. The site
team would put the
preventative measures into
action by involving in
software installation and
providing training to the
organizational personnel.
Courses of Action Table
No.
Attack
Phase
Attack Action
Compro
mise
indicato
rs
Detection
point
Defensive
countermeasures
Defense
phase
1
Targeting
Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web server
logs (public
systems)
Perimeter
firewall
logs
Keeping check of
malicious or
suspicious log
addresses
Applying
temporary block
on suspicious log
addresses
Documenting
findings and
action taken
Preparation
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information on
the possible
targets
Applying tools
like Nmap for
scanning target
systems to
Detectio
n of
external
scans in
traffic
patterns
The rise
in
Social
SIEM
platform or
Intrusion
Detection
and
Prevention
System
(IDPS)
Ensuring SIEM
platform or
Intrusion
Detection and
Prevention
System is updated
Introducing and
implementing
strict physical
Identification
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 8
identify open
ports or other
vulnerabilities.
Engineer
ing
attempts
to collect
more
informati
on from
personne
l
High user
reports
relating to
suspicious
activities
access policies
and practices.
Ensuring
outsiders or
visitors are
allowed to enter
into personnel
premise.
The receptionist
has to make sure
that visitors do
not sneak into the
“Employee only”
area.
Documentation
of all the findings
and actions taken
by conducting a
thorough analysis
of the security
incident.
3
Weaponizati
on
Downloading,
or installing a
tool which
unifies an
exploit with
malware and
gives rise to
the deliverable
payload.
Choosing
correct
vulnerabilities
based on the
previous stage.
Abnorma
l issues
and
performa
nce-
related
issues
Detectio
n of
suspiciou
s files
Logged
connecti
ons with
maliciou
s IP
addresse
s.
SIEM logs
that have
identified
connections
with
suspicious
IP
addresses
Endpoint
antivirus
warnings
and alerts
Ensuring anti-
virus is updated
Regularly
assessing log and
file history
Documentation
of all the findings
and actions taken
after conducting
a thorough
analysis of the
security incident.
Identification
4
Exploitation
After the
payload is
established
and deployed
to the targeted
system, the
built-in exploit
gets activated
to compromise
the intended
target
The anti-
virus
detection
of
suspiciou
s files,
especiall
y the
ones that
have
been
Logs or
anti-virus
endpoints
detecting
suspicious
files which
are located
on endpoint
devices. f
SIEM logs
identifying
Employment of a
new and updated
anti-virus or anti-
malware platform
which will have
the potential to
capture as well as
quarantine
malicious or
suspicious code
executions.
Identification
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 9
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
of users.
Identific
ation of
maliciou
s or
suspiciou
s files in
common
locations
.
Detectio
n of
abnormal
behavior
at
endpoint
s
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to peculiar
or strange
IP
addresses
Offer users and
employees with
proper security
awareness
training. They
need to be
updated about the
latest security
threats that are
emerging in the
cyber world. f
Introducing a
strict user access
policy so that
they can carry out
their
responsibilities in
an effective
manner.
Documenting the
findings and
actions taken by
conducting a
thorough analysis
of the security
incident.
5
Installation
Establishment
of a secure
control over
the target
system by
using specific
malware like
Remote
Access Trojan.
Taking
advantage of
the position to
continue
havening
access into the
system.
Identific
ation of
maliciou
s or
suspiciou
s
processe
s that are
running
on the
system.
Abnorma
l
behavior
identifie
d at
endpoint
s
SIEM logs
identifying
connections
with
malicious
IP
addresses
Windows
Event log
highlights
activities
and events
at hours
when the
system
should have
been idle.
Designing a
deploying a
robust audit
process for
identifying
suspicious or
malicious
processes on the
system.
Making sure that
the available
Intrusion
Detection and
Prevention
System (IDPS)
updates are
installed on an
Containment
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 10
Performa
nce
issues
on-going basis on
the system.
Hardening the
organization’s
network by
closing all the
ports that are not
needed to carry
out the legal
activities of the
business.
Documenting all
the findings and
actions relating to
the security
incident.
6
Command
and Control
Building a
communicatio
n network
between the
target system
and the
attacker
system to
access the
functional
aspects of the
target system.
The ports for
social media
and cloud
applications
work fine as
they have high
bandwidth
which is
because they
are left open.
This makes it
difficult to
identify
suspicious
activities.
Identific
ation of
abnormal
behavior
at the
endpoint
Performa
nce
issues
Running
of
suspiciou
s
processe
s on the
system.
Logs
revealing
a
connecti
on to
maliciou
s IP
addresse
s.
SIEM logs
identifying
connections
with
suspicious
IP
addresses.
Windows
Event log
shows
activities at
hours when
the system
should have
been idle.
Large data
transfers
revealed by
logs
Employment of
proxy servers for
varying kinds of
access.
Analysis of logs
Command and
Control to tailor
the blocking
mechanism.
Perimeter
firewall logs
show outbound
connections.
Documentation
of all the findings
and actions taken
by conducting
thorough analysis
of the security
incident.
Containment
7
Achieving
the objective
Using proper
controls over
the target
system for
accomplishing
Creation
of
unauthor
ized
accounts
at the
Abnormal
endpoint
behavior
Windows
Event log
reveals
Tracing the
mobility of files
that were copied,
moved or deleted.
Identification of
whether the
Eradication
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 11
the chief target
objective.
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnorma
l file
activity
Corrupte
d or
destroye
d data
found on
the
system
Complet
e denial
of access
to
system
resources
f
activities at
hours when
it should
not be used
SIEM logs
recognizing
malicious
IP
addresses.
compromised
data contained
sensitive
information or
not.
Creating
effective process
relating to
incidence
response.
Documentation
of all the findings
and actions taken
by conducting a
thorough analysis
of the security
incident.
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is extremely vital to
maintain the quality of the security infrastructure. After making sure that a proper remedy is in
place, it is necessary for the security professionals to make sure that a proper documentation
approach is followed which captures all the details relating to the incident. In fact, it would
assist to devise suitable policies and practices in the organizational setting so that similar
kinds of security incidents could be avoided in the future. The existence of proper
documentation of the entire event would also help to critically evaluate the security incident
and arrive at the findings which can help to strengthen the overall effectiveness of the security
framework of the business entity that is highlighted in the Cybersecurity Incident Response
Plan.
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 12
The comprehensive assessment of the entire security incident can enable the security
professionals to get an in-depth insight into the vulnerabilities that were exploited. They will
be empowered to take robust decisions relating to incidence response. The documentation of
appropriate findings will act as the guideline which will help the professionals to take suitable
measures to prevent similar security breach incidents.
Communications plan
The careful and accurate documentation of the actions and steps is necessary as it can
assist to devise proper strategies, policies, and protocols or the business undertaking. In
addition to this, it is necessary to effectively articulate and communicate about the security
incident to the key stakeholders. Their knowledge on the sensitive subject matter is of
paramount importance and this will be possible by making sure a robust documentation
process is in place. On the basis of the nature and type of the cybersecurity incident that took
place, the involved stakeholders must be given necessary information that will be relevant for
them.
For example, in case a security incident compromises private and sensitive
information, it is necessary to take into consideration legislation and regulations so that it can
identify who are the parties that must be notified about the security incident. According to the
Federal Trade Commission, good communication is necessary so that the concern and
frustration of the customers can be limited to a certain degree (Data Breach Response: A
Guide for Business, 2019). In the organizational setting, it is necessary to intimate the suitable
personnel about the security breach incident. The information sharing would help to take
necessary measures so that the degree of vulnerability could be contained. As the information
relating to the security incident might have a different degree of relevance for the involved
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 13
parties, a thorough documentation would enable the personnel to get a comprehensive idea
about the incident and associated implications.
Countermeasures Analysis
The proper introduction and execution of the countermeasures would help to
effectively curb the online threats and risks. In addition to this, it would also help to strengthen
the existing security policies and practices that are implemented in the organizational setting.
The countermeasures have been designed so that the negative implication on various elements
could be limited such as organizational Systems, organizational operations, and organizational
personnel.
Reduced negative impact on Organizational Systems
The security analysts are supposed to carefully analyse the activities that are
conducted on the organizational network. Such a countermeasure would play a critical role to
make sure that malicious and suspicious activities or behaviour could be identified right from
the start. This approach would be necessary to make sure that the gaps that could exist in the
Organizational Systems can be identified and suitable actions can be taken to mitigate the
security problem (Antivirus Best Practices, 2019).
The application of necessary security tools such as Nmap would help to conduct the
scanning activities so that the target could be identified and suitable measures could be taken
by the Information Technology department for taking effective actions so that the
organizational system would not get compromised. Similarly, the use of the most effective
anti-virus or anti-malware platform in the business setting would ensure that the system
functions in an efficient and secure manner (Antivirus Best Practices, 2019).
Reduced negative impact on Organizational Operations
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 14
By making sure that all the security tools and applications are effective to deal with the
vulnerabilities and threats, they must be regularly updated. Similarly, the proper check of the
IP addresses that are a part of the network would help to identify any suspicious or malicious
activity that would be evident in the firm’s Information Technology infrastructure. The proper
maintenance of the IP logs would help the Network Administrators to capture any activities
that are not related to the business activities and processes. f Such a holistic approach would be
vital to minimizing the extent of negative impact on the operational activities that are carried
out by the business undertaking.
The use of the Intrusion Detection and Prevention System (IDPS) would play a critical
role to minimize the adverse impact of the security attack on organizational operations. These
vital tools would primarily help to identify suspicious and malicious activities that could exist
in the IT ecosystem of the business undertaking and negatively impact the operations and
processes.
Reduced negative impact on Organizational Personnel
The effective implementation of physical access controls would make sure that the
security policies and protocols are in place. By restricting the movement of outsiders or
visitors, the organization could ensure that confidential and sensitive business information
would not get leaked to outsiders. By carefully keeping a check on the movement of
employees as well as outsiders in the organizational premises, it would be easier to introduce
suitable security measures and strategies so that the adverse impact on the organizational
personnel could be reduced or completely mitigated. Addition security cameras and CCTVs
could be installed so that the security personnel could assess the actions of the personnel and
identify any kind of abnormal action or behaviour in the organizational context. In addition to
the physical access policy, a robust user access policy would ensure that unauthorized
personnel do not gain access to confidential business information. The proper documentation
ISE 620 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 15
of all the processes would make sure that the personnel of the organization is well informed
about the security actions that should be taken in case a security breach incident takes place in
the future. Such an approach would primarily empower the employees as they would be
prepared to take necessary actions which could minimize the overall vulnerability of the
business undertaking in the uncertain cyber setting.
References
Antivirus Best Practices. (2019). Retrieved September 27, 2019, from
ncb.mu/English/Documents/Downloads/Reports and Guidelines/Anti Virus Best
Practices.pdf
Data Breach Response: A Guide for Business. (2019). Federal Trade Commission. Retrieved
23 September 2019, from https://www.ftc.gov/tips-advice/business-
center/guidance/data-breach-response-guide-business