Cyberstudy
PDF p.298 In progress

Preparation

Open PDF at p.298 23 flashcards

Summary

PDF p.298

The preparation process establishes and updates policies and procedures for dealing with security breaches, including provisioning personnel and resources.

In plain words

Supplementary — not from your PDF

Preparation provides the people, tools and plans before anything happens. Tools cover detection (visibility), forensics (acquiring and validating evidence) and case management. The CIRT/CSIRT includes managers, analysts and technicians, and draws on legal, HR and PR. A communication plan uses out-of-band channels so attackers aren't tipped off, and stakeholder management controls what is released and who must be notified. The result is a formal incident response plan.

Detailed explanation

PDF p.298

Cybersecurity Infrastructure

  • Incident Detection Tools: Provide visibility by automating the collection and analysis of network traffic, system state monitoring, and log data.
  • Digital Forensics Tools: Facilitate acquiring and validating data from system memory and file systems for incident response or prosecution.
  • Case Management Tools: Log incident details and coordinate response activities across a team. Often part of a product suite like SIEM or SOAR, which manage incident response steps.

Cyber Incident Response Team

  • Team Composition: Includes members with various security competencies, often referred to as CIRT, CSIRT, or CERT. May be part of a SOC.
  • Leadership: Led by a senior executive decision-maker for serious incidents.
  • Roles
    • Managers: Oversee daily operations and coordinate with other departments.
    • Analysts and Technicians: Prioritize cases and mitigate minor incidents.
  • Additional Expertise
    • Legal: Ensures compliance with laws and regulations, liaises with law enforcement.
    • Human Resources (HR): Manages employee-related issues and contributes to addressing underlying organizational problems.
    • Public Relations: Handles negative press and social media reactions.
  • Outsourcing: Some functions may be outsourced to third-party agencies for better handling of insider threats.

Communication Plan

  • Purpose: Establishes clear lines of communication for reporting incidents and notifying affected parties.
  • Security: Prevents unintentional information release and ensures adversaries are not alerted to containment measures.
  • Out-of-Band Communication: Uses methods that cannot be intercepted, avoiding corporate email.

Stakeholder Management

  • Information Control: Prevents unauthorized release of incident details.
  • Reporting Obligations: Informs affected parties and regulators as necessary.
  • Marketing and PR Impact: Manages the company's reputation and demonstrates improved security systems.

Incident Response Plan

  • Outcome: A formal plan listing procedures, contacts, and resources for various incident categories.

Important terms

taken from the text above
Incident Detection Tools
Provide visibility by automating the collection and analysis of network traffic, system state monitoring, and log data.
Digital Forensics Tools
Facilitate acquiring and validating data from system memory and file systems for incident response or prosecution.
Case Management Tools
Log incident details and coordinate response activities across a team. Often part of a product suite like SIEM or SOAR, which manage incident response steps.
Team Composition
Includes members with various security competencies, often referred to as CIRT, CSIRT, or CERT. May be part of a SOC.
Leadership
Led by a senior executive decision-maker for serious incidents.
Managers
Oversee daily operations and coordinate with other departments.
Analysts and Technicians
Prioritize cases and mitigate minor incidents.
Legal
Ensures compliance with laws and regulations, liaises with law enforcement.
Human Resources (HR)
Manages employee-related issues and contributes to addressing underlying organizational problems.
Public Relations
Handles negative press and social media reactions.
Outsourcing
Some functions may be outsourced to third-party agencies for better handling of insider threats.
Out-of-Band Communication
Uses methods that cannot be intercepted, avoiding corporate email.
Information Control
Prevents unauthorized release of incident details.
Reporting Obligations
Informs affected parties and regulators as necessary.
Marketing and PR Impact
Manages the company's reputation and demonstrates improved security systems.
HR Human Resources

Examples & real-world scenarios

Supplementary — not from your PDF
  • A call tree using personal phones in case corporate email is compromised.
  • Legal on standby to handle regulator notification.
  • Case management software tracking each incident.

Scenario

During a breach, responders discuss containment over corporate email, which the attacker is reading. An out-of-band communication plan would have prevented tipping them off.

Common mistakes

Supplementary — not from your PDF
  • Assuming IR is purely technical. Legal, HR and PR roles matter.
  • Using potentially compromised channels to coordinate the response.

Practical skills

Supplementary — not from your PDF
  • Outline an IR plan's contents and team roles.

What I should remember

Key Points PDF p.298
  • Cybersecurity Infrastructure
    • Incident Detection: Automates data collection and analysis.
    • Digital Forensics: Validates data for response or prosecution.
    • Case Management: Coordinates response activities.
  • Cyber Incident Response Team
    • Composition: Security experts, legal, HR, PR.
    • Leadership: Senior executive decision-maker.
    • Roles: Managers, analysts, technicians.
    • Outsourcing: Third-party agencies for insider threats.
  • Communication Plan
    • Purpose: Clear reporting lines.
    • Security: Prevents information leaks.
    • Out-of-Band: Secure communication methods.
  • Stakeholder Management
    • Control: Prevents unauthorized information release.
    • Reporting: Informs affected parties and regulators.
    • PR Impact: Manages reputation.
  • Incident Response Plan
    • Outcome: Formal plan with procedures and resources.