SECOPS 13: Incident Response Plan Flashcards
IR Plan questions (4)
Assets to protect?
Threats to assets?
How are threats detected?
Response to threats?
IR Lifecycle (7)
Preparation Identification Analysis Containment Eradication/Recovery Lessons Learned Reporting
Preparation phase
Get ready to handle an incident
Identification phase
Monitoring and hunting
Analysis phase
Preform analysis and determine scope
Containment phase
Determine best containment steps.
Hardest decision
Eradication and Recovery
Find root cause and clean it up (hardening, etc.).
Lessons learned
How and why? Conduct FMEA
FMEA
Failure Mode and Effects Analysis. Qualitative tool in a spreadsheet documenting what might go wrong.
Reporting phase
IR Team notifies appropriate individuals
Attrition attack vector
Brute force. DDOS
Improper usage
Incident from violation of AUP.
Impersonation attack vector
Replacing something benign with something malicious. Spoofing, MITM, rogue wireless, some SQL injection
US-CIRT reporting Testing (CAT and time)
CAT 0. n/a
US-CIRT reporting Unauthorized Access (Cat and time)
CAT 1. 1 Hour