Preparation
Summary
PDF p.298The preparation process establishes and updates policies and procedures for dealing with security breaches, including provisioning personnel and resources.
In plain words
Supplementary — not from your PDFPreparation provides the people, tools and plans before anything happens. Tools cover detection (visibility), forensics (acquiring and validating evidence) and case management. The CIRT/CSIRT includes managers, analysts and technicians, and draws on legal, HR and PR. A communication plan uses out-of-band channels so attackers aren't tipped off, and stakeholder management controls what is released and who must be notified. The result is a formal incident response plan.
Detailed explanation
PDF p.298Cybersecurity Infrastructure
- Incident Detection Tools: Provide visibility by automating the collection and analysis of network traffic, system state monitoring, and log data.
- Digital Forensics Tools: Facilitate acquiring and validating data from system memory and file systems for incident response or prosecution.
- Case Management Tools: Log incident details and coordinate response activities across a team. Often part of a product suite like SIEM or SOAR, which manage incident response steps.
Cyber Incident Response Team
- Team Composition: Includes members with various security competencies, often referred to as CIRT, CSIRT, or CERT. May be part of a SOC.
- Leadership: Led by a senior executive decision-maker for serious incidents.
-
Roles
- Managers: Oversee daily operations and coordinate with other departments.
- Analysts and Technicians: Prioritize cases and mitigate minor incidents.
-
Additional Expertise
- Legal: Ensures compliance with laws and regulations, liaises with law enforcement.
- Human Resources (HR): Manages employee-related issues and contributes to addressing underlying organizational problems.
- Public Relations: Handles negative press and social media reactions.
- Outsourcing: Some functions may be outsourced to third-party agencies for better handling of insider threats.
Communication Plan
- Purpose: Establishes clear lines of communication for reporting incidents and notifying affected parties.
- Security: Prevents unintentional information release and ensures adversaries are not alerted to containment measures.
- Out-of-Band Communication: Uses methods that cannot be intercepted, avoiding corporate email.
Stakeholder Management
- Information Control: Prevents unauthorized release of incident details.
- Reporting Obligations: Informs affected parties and regulators as necessary.
- Marketing and PR Impact: Manages the company's reputation and demonstrates improved security systems.
Incident Response Plan
- Outcome: A formal plan listing procedures, contacts, and resources for various incident categories.
Important terms
taken from the text above- Incident Detection Tools
- Provide visibility by automating the collection and analysis of network traffic, system state monitoring, and log data.
- Digital Forensics Tools
- Facilitate acquiring and validating data from system memory and file systems for incident response or prosecution.
- Case Management Tools
- Log incident details and coordinate response activities across a team. Often part of a product suite like SIEM or SOAR, which manage incident response steps.
- Team Composition
- Includes members with various security competencies, often referred to as CIRT, CSIRT, or CERT. May be part of a SOC.
- Leadership
- Led by a senior executive decision-maker for serious incidents.
- Managers
- Oversee daily operations and coordinate with other departments.
- Analysts and Technicians
- Prioritize cases and mitigate minor incidents.
- Legal
- Ensures compliance with laws and regulations, liaises with law enforcement.
- Human Resources (HR)
- Manages employee-related issues and contributes to addressing underlying organizational problems.
- Public Relations
- Handles negative press and social media reactions.
- Outsourcing
- Some functions may be outsourced to third-party agencies for better handling of insider threats.
- Out-of-Band Communication
- Uses methods that cannot be intercepted, avoiding corporate email.
- Information Control
- Prevents unauthorized release of incident details.
- Reporting Obligations
- Informs affected parties and regulators as necessary.
- Marketing and PR Impact
- Manages the company's reputation and demonstrates improved security systems.
Examples & real-world scenarios
Supplementary — not from your PDF- A call tree using personal phones in case corporate email is compromised.
- Legal on standby to handle regulator notification.
- Case management software tracking each incident.
Scenario
During a breach, responders discuss containment over corporate email, which the attacker is reading. An out-of-band communication plan would have prevented tipping them off.
Common mistakes
Supplementary — not from your PDF- Assuming IR is purely technical. Legal, HR and PR roles matter.
- Using potentially compromised channels to coordinate the response.
Practical skills
Supplementary — not from your PDF- Outline an IR plan's contents and team roles.
What I should remember
Key Points PDF p.298-
Cybersecurity Infrastructure
- Incident Detection: Automates data collection and analysis.
- Digital Forensics: Validates data for response or prosecution.
- Case Management: Coordinates response activities.
-
Cyber Incident Response Team
- Composition: Security experts, legal, HR, PR.
- Leadership: Senior executive decision-maker.
- Roles: Managers, analysts, technicians.
- Outsourcing: Third-party agencies for insider threats.
-
Communication Plan
- Purpose: Clear reporting lines.
- Security: Prevents information leaks.
- Out-of-Band: Secure communication methods.
-
Stakeholder Management
- Control: Prevents unauthorized information release.
- Reporting: Informs affected parties and regulators.
- PR Impact: Manages reputation.
-
Incident Response Plan
- Outcome: Formal plan with procedures and resources.