short answer
Incident Response Planning
Incident response planning includes identification of, classification of, and response to an incident.
· Attacks classified as incidents if they:
· Are directed against information assets
· Have a realistic chance of success
· Could threaten confidentiality, integrity, or availability of information resources
· Incident response (IR) is more reactive than proactive, with the exception of planning that must occur to prepare IR teams to be ready to react to an incident.
Incident Response Planning (cont’d)
· Incident response policy identifies the following key components:
· Statement of management commitment
· Purpose/objectives of policy
· Scope of policy
· Definition of InfoSec incidents and related terms
· Organizational structure
· Prioritization or severity ratings of incidents
· Performance measures
· Reporting and contact forms
Incident Response Planning (cont’d)
· Incident Planning
· Predefined responses enable the organization to react quickly and effectively to the detected incident if:
· The organization has an IR team
· The organization can detect the incident
· IR team consists of individuals needed to handle systems as incident takes place.
· Incident response plan
· Format and content
· Storage
· Testing
Incident Response Planning (cont’d)
· Incident detection
· Most common occurrence is complaint about technology support, often delivered to help desk.
· Careful training is needed to quickly identify and classify an incident.
· Once incident is properly identified, the organization can respond.
· Incident indicators vary.
Incident Response Planning (cont’d)
· Incident reaction
· Consists of actions that guide the organization to stop incident, mitigate its impact, and provide information for recovery
· Actions that must occur quickly:
· Notification of key personnel
· Documentation of the incident
· Incident containment strategies
· Containment of incident’s scope or impact as first priority; must then determine which information systems are affected
· Organization can stop incident and attempt to recover control through a number or strategies.
Incident Response Planning (cont’d)
· Incident recovery
· Once incident has been contained and control of systems regained, the next stage is recovery.
· The first task is to identify human resources needed and launch them into action.
· Full extent of the damage must be assessed.
· Organization repairs vulnerabilities, addresses any shortcomings in safeguards, and restores data and services of the systems.
Incident Response Planning (cont’d)
· Damage assessment
· Several sources of information on damage can be used, including system logs, intrusion detection logs, configuration logs and documents, documentation from incident response, and results of detailed assessment of systems and data storage.
· Computer evidence must be carefully collected, documented, and maintained to be usable in formal or informal proceedings.
· Individuals who assess damage need special training.
Incident Response Planning (cont’d)
· Automated response
· New systems can respond to incident threat autonomously.
· Downsides of current automated response systems may outweigh benefits.
· Legal liabilities of a counterattack
· Ethical issues
Disaster Recovery Planning
· Disaster recovery planning (DRP) is preparation for and recovery from a disaster.
· The contingency planning team must decide which actions constitute disasters and which constitute incidents.
· When situations are classified as disasters, plans change as to how to respond; take action to secure most valuable assets to preserve value for the longer term.
· DRP strives to reestablish operations at the primary site.
Page 1 of 1
Page
1
of
1
Incident Response Planning
Incident response planning includes identification of, cl
assification of, and response to an
incident.
•
Attacks classified as incidents if they:
–
Are directed against information assets
–
Have a realistic chance of success
–
Could threaten confidentiality, integrity, or availability of information resources
•
Incident response (IR) is more reactive than proactive, with the exception of planning that
must occur to prepare IR teams to be ready to react to an incident.
Incident Response Planning (cont’d)
•
Incident response policy identifies the follo
wing key components:
–
Statement of management commitment
–
Purpose/objectives of policy
–
Scope of policy
–
Definition of InfoSec incidents and related terms
–
Organizational structure
–
Prioritization or severity ratings of incidents
–
Performance measures
–
Reporting and contact forms
Incident Response Planning (cont’d)
•
Incident Planning
–
Predefined responses enable the organization to react quickly and effectively to
the detected incident if:
•
The organization has an IR team
•
The organization can detect the incident
–
IR team consists of individuals needed to handle systems as incident takes place.
•
Incident response plan
–
Format and content
–
Storage
–
T
esting
Incident Response Planning (cont’d)
•
Incident detection
–
Mo
st common occurrence is complaint about technology support, often delivered
to help desk.
–
Careful training is needed to quickly identify and classify an incident.
–
Once incident is properly identified, the organization can respond.
–
Incident indicators vary.
Incident Response Planning (cont’d)
•
Incident reaction
–
Consists of actions that guide the organization to stop incident, mitigate its
impact, and provide informat
ion for recovery
–
Actions that must occur quickly:
•
Notification of key personnel
•
Documentation of the incident
•
Incident containment strategies
Page 1 of 1
Incident Response Planning
Incident response planning includes identification of, classification of, and response to an
incident.
• Attacks classified as incidents if they:
– Are directed against information assets
– Have a realistic chance of success
– Could threaten confidentiality, integrity, or availability of information resources
• Incident response (IR) is more reactive than proactive, with the exception of planning that
must occur to prepare IR teams to be ready to react to an incident.
Incident Response Planning (cont’d)
• Incident response policy identifies the following key components:
– Statement of management commitment
– Purpose/objectives of policy
– Scope of policy
– Definition of InfoSec incidents and related terms
– Organizational structure
– Prioritization or severity ratings of incidents
– Performance measures
– Reporting and contact forms
Incident Response Planning (cont’d)
• Incident Planning
– Predefined responses enable the organization to react quickly and effectively to
the detected incident if:
• The organization has an IR team
• The organization can detect the incident
– IR team consists of individuals needed to handle systems as incident takes place.
• Incident response plan
– Format and content
– Storage
– Testing
Incident Response Planning (cont’d)
• Incident detection
– Most common occurrence is complaint about technology support, often delivered
to help desk.
– Careful training is needed to quickly identify and classify an incident.
– Once incident is properly identified, the organization can respond.
– Incident indicators vary.
Incident Response Planning (cont’d)
• Incident reaction
– Consists of actions that guide the organization to stop incident, mitigate its
impact, and provide information for recovery
– Actions that must occur quickly:
• Notification of key personnel
• Documentation of the incident
• Incident containment strategies