- Digital Forensics and Incident Response
- Gerard Johansen
- 457字
- 2021-07-02 18:49:44
The incident response plan
With the incident response charter written and the CSIRT formed, the next step is to craft the incident response plan. The incident response plan is the document that outlines the high-level structure of an organization's response capability. This is a high-level document that serves as the foundation of the CSIRT. The major components to the incident response plan are:
- Incident response charter: The incident response plan should include the mission statement and constituency from the incident response charter. This gives the plan continuity between the inception of the incident response capability and the incident response plan.
- Expanded services catalog: The initial incident response charter had general service categories with no real detail. The incident response plan should include specific details of what services the CSIRT will be offering. For example, if forensic services are listed as part of the service offering, the incident response plan may state that forensic services include the evidence recovery from hard drives, memory forensics, and reverse engineering potentially malicious code in support of an incident. This allows for the CSIRT to clearly delineate between a normal request, say for the searching of a hard drive for an accidentally deleted document not related to an incident, and the imaging of a hard drive in connection with a declared incident.
- CSIRT personnel: As was outlined before, there are a great many individuals who comprise the CSIRT. The incident response plan will clearly define these roles and responsibilities. Organizations should expand out from just a name and title and define exactly the roles and responsibilities of each individual. It is not advisable to have a turf war during an incident and having the roles and responsibilities of the CSIRT personnel clearly defined goes a long way to reducing this possibility.
- Contact list: An up- to-date contact list should be part of the Incident Response Plan. Depending on the organization, the CSIRT may have to respond to an incident 24 hours a day. In this case, the Incident Response Plan should have primary and secondary contact information. Organizations can also make use of a rotating on-call CSIRT member who could serve as the first contact in the event of an incident.
- Internal communication plan: Incidents can produce a good deal of chaos as personnel attempt to ascertain what is happening, what resources they need, and who to engage to address the incident. The incident response plan internal communication guidance can address this chaos. This portion of the plan addresses the flow of information upward and downward between senior leadership and the CSIRT. Communications sideways between the CSIRT core and support personnel should also be addressed. This limits the individuals who are communicating with each other and cuts down on potentially conflicting instructions.
推薦閱讀
- Mastering JavaScript Functional Programming
- Learning Apex Programming
- Building Modern Web Applications Using Angular
- Python程序設計(第3版)
- Elastic Stack應用寶典
- C語言程序設計案例式教程
- Visual Basic學習手冊
- Oracle JDeveloper 11gR2 Cookbook
- 深入淺出React和Redux
- Python全棧數據工程師養成攻略(視頻講解版)
- 從0到1:HTML5 Canvas動畫開發
- Flink技術內幕:架構設計與實現原理
- Flask Web開發:基于Python的Web應用開發實戰(第2版)
- Hack與HHVM權威指南
- JSP編程教程