Module 5 - Incident Response Cycle Flashcards
Characterize the National Incident Response (IR) Plan Evaluate the strengths and weaknesses of triaging incident response data and what is necessary to have that data incorporated into a national-level IR plan Create a port-to-process map Explain how the Federal Rules of Evidence impact the use of tools
- Phases of National Incident Response Plan
Prevent & Protect Detect Analysis Respond Resolve
- Overarching themes of NIRP
coordination across landscape and common operational picture (COP).
- Requires active participation
- not just within an organization
- COP (acronym)
common operation picture
Risk Alert System Tiers
guarded
elevated
substantial
severe
- Triage
Part of detection phase
Way to get around problem of large amounts of data
In order for it to work:
1) triage must be reliable
2) must be customized for organization
To integrate results at national, must have common framework (ontology)
Incident Response Stages
Preparation
Incident Identification
Treatment of Incident
Post-mortem
(iterative, more prep reduces other steps)
NIST Four Stage
Preparation
Detection and Analysis
Containment, eradication, and recovery
Post-incident recovery
Others: Preparation Identification Containment Eradication Recovery Lessons Learned/Follow-up
National Cyber IR Plan
- Headed by DHS
Coordination
- owner/operator of critical infrastructure and key resources focused on containment and recovery
- Federal partners may be focused on attribution & prosecution
NCCIC
National Cybersecurity and Communications Integration Center (Prevent and Protect)
monitors:
threats, vulnerabilities, disruptions, and intrusions
Detect phase
owners work independently within their IR programs, when appropriate in partnership with others
Analysis
determine whether incident was malicious or unintentional
3 Phase Assessment: impact, scope, severity
rolling up information
Response
Mutual agreement
each org in Significant Cyber Incident has role
National Cyber Risk Alert Levels
NCRAL
1 - Severe
2- Substantial
3 - Elevated
4 - Guarded
Significant cyber Incident
a set of conditions in the cyber domain that requires increased national coordination
- triggered when the NCRAL system reaches level 2.