On another note, with respect to incident response
management, the purpose is to provide a plan for a clear path of resolving a
security breach. According to the Special Publication NIST 800-61 Rev. 2, the
first thing that an organization should do is establish a clear organizational
meaning of the word “incident”. It provides a guide to incident handling and recommends
establishing response capabilities, incident response policies, an IR plan,
procedures, information sharing mechanisms, team structure and even collaboration
with external groups. The team’s structure, the services they provide along
with the policies and procedures are established. This team consists of:
internet service providers, incident reporters, law enforcement agencies,
software and support vendors, customers and media as well as other teams.
The recommended incident handling procedure consists of: preparation,
detection and analysis, containment, eradication and recovery. During the
preparation phase, the selection of team members, necessary training, tools and
resources are acquired. There are
various attack vectors that attackers can use to exploit a vulnerability, hence
systems should be in place to detect and alert when there is a potential
attack. Once at event is considered an attack, the team should immediately
start documenting the facts concerning the incident. At the same time,
notifications should be sent out alert relevant facets of the team. Then, the
first action should be an attempt to contain the incident from spreading to
other systems, after which eradication and recovery of compromised systems
should occur. A critical step, is post activity where the team can learn from
the incident and report to other organizations. Moreover, there should be some
level of evidence containment for a period of time. NIST SP 800-61 Rev. 2 also
provides an incident handling checklist which can be very useful to
organizations adopting a similar approach. As can be see, incident response
provides a clear, consistent, systematic approach to dealing with events that
attempt to wreak havoc on the daily operations of a business.
Wow... NIST really done a great job for incident response.I really find this blog post very informative on NIST incident response. Thanks for sharing
ReplyDelete