9 - 1: Incident Response Programs Flashcards
NIST Special Publication 800-61
Standard incident handling process
Incident Response Plan
Structure and guidance for responding to incidents
Incident Response Plan elements
1) Statement of purpose/scope 2) clear strategies and goals 3) Approach to responses 4) Approval from Sr management
Service providers
Round out areas where services within the organization are needed
Communication plan
Ensure the right people are informed of and during a cybersecurity incident. Who AND how
Involving law enforcement
Complex question as it may make some details public
Incident communications
Make sure they’re confidential and don’t risk alerting attackers
SIEM
Security Incident and Event Manager, coordinates information from a variety of sources - firewalls, IDS/IPS, event logs - to collect and analyze data for activity
Incidents may also be reported from ____ sources
External
Incident first response
Isolate the system, allow it to continue to run, but do not keep it connected to the network
Incident first response priority
Contain damage through isolation
Counterintelligence
As adversaries are trying to learn about your network, some organizations have programs to hinder or provide false information
Escalation and notification objectives
1) Evaluate severity 2) Escalate appropriately 3) Notify stakeholders
Low-impact events
Usually would not involve an after-hours response
Medium-impact events
Likely to have a security impact