10 - Incident Management Flashcards
What is an incident?
Any event that violates an org’s security policies.
May disrupt normal operations
Cycle of diaster planning/recovery (3 things)
- Planning
- Disaster
- Recovery
Planning process
RCIDP
- Risk assessment
- Conduct aq business impact analysis
- Identify preventative controls
- Develop IT recovery and reconsitution strategy
- plann testing, training, maintenance and exercises
Business Impact Analysis
Determines the impact in the event that key processes are not available
Built on worst case scenarios: what assets needed to recover?
Identify recovery time (maximum down time)
3 steps of BIA
Assess and analyse
Report
Develop Policies
Business COntinuity Plan
Creates a plan to continue business after disaster
Recovery time objective
How quickly business process should be recovered, based on business tolerance to loss.
Recovery Point Objective
Defines the maximum acceptable level of data loss
Incident response plan helps to do what
helps to identify the security event and bring it to closure
Disaster Recovery Plan
How an org manages a catastrophic event, such as a natural disaster or accidental data loss
GDPR requires a backup and disaster recovery plan. What is the maximum time for informing authorities of a breach?
72 hours
SANS Institute’s 6 steps of incident response
PICERL
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons Learned
Incident Response reactive and/or proactive?
reactive (handling incidents as they occur) but also proactive (prepare/prevent)
Backup considerations
- Frequency
- Location
- Medium
- Vaulting
- Mirroring
- What to backup
Redundant/Mirrored
Mirror of original
Fully available
Real time info mirroring
Drawbacks:
Expensive
Hot site & drawbacks
- Fully configured
- Readily available
- annually tested
Drawbacks:
- Expensive
- Hardware/software choices limited
- Short term
Warm Site
- Partially Configured
- Long term
- Choice of hardware/software use
Drawbacks:
- Not readily available
- No testing
- Resources not available
Cold Site
- Core equipment only
Drawbacks
- take up to a week
- Operation resources not available
Mobile/rolling site
- Transportable with necessary hardware and equipment
Drawbacks:
- Short term
Disaster Declaration Policy
Outlines the process by with BCP and DRP are activated
Defines the roles and responsibilities for assessing/declaring disaster.
Includes notification of people and alternate site activations
Forensic Investigation
who, what, when, where, how and why etc
Evidence…:
- Collection
- Preservation
- Analysis
- Presentation
What to do after the incident
Review readiness for next incident
Review risk management and security policies
Further investigation
SANS report format
- When and who
- scope
- how contained/eradicated
- recovery work
- effective response areas
- areas of improvement