Lecture 7 Incident Response

Incident Response Lecture 7


What is an Incident?

  • A computer security incident is any action or activity—accidental or deliberate—that compromises the confidentiality, integrity, or availability of data and IT resources.

  • Includes activities such as:

    • Fraud

    • Child pornography

    • Theft

    • Hacking

  • Policy violations may also be considered security incidents.


Incident Response Plan (IRP)

  • An IRP ensures the right personnel and procedures are in place for effectively handling security breaches as they occur.

  • Provides a targeted response to contain and remove threats.

  • Backup Data: Identify and back up critical data in a remote location (like the cloud).

    • Prioritization of backups is crucial.

  • Employees must understand their roles during a cyber incident for quick recovery.


Team Leadership and Duties

  • CISO or Operations Team Lead typically acts as the CSIRT Leader.

    • Tasks include:

      • Convene the CSIRT (Computer Security Incident Response Team)

      • Select additional support members as necessary

      • Contact the Chief Information Officer (CIO)

      • Conduct and document meetings

      • Manage incidents and ensure proper documentation

      • Report status to the CIO

      • Train team continuously

      • Conduct debriefings and report lessons learned


Team Expertise

  • Various team members may be involved such as:

    • Registrar

    • Public Information Officer

    • Platform Specialists

    • Financial Administrators

    • Law Enforcement

    • CIO

    • Chief Auditor Office

    • Legal

    • Human Resources

    • Information Security (CISO or Representative)


Incident Response Goals

  • Preserve the confidentiality, integrity, and availability of enterprise information.

  • Minimize organizational impact.

  • Provide management with pertinent information for decision-making.

  • Ensure a structured, logical, repeatable, and successful approach to incidents.

  • Improve efficiency and effectiveness of incident management.

  • Mitigate financial and human resource impacts.

  • Gather evidence for potential legal and liability issues.


Incident Models

  • Utilize predefined incident models to handle recurring incidents effectively.

  • Necessary components of the model:

    • Steps in chronological order for incident handling.

    • Defined responsibilities for team members.

    • Timelines for action completion.

    • Escalation procedures.

    • Evidence preservation activities.


Incident Management Process

  • The process consists of:

    • Incident Identification, Logging, and Categorization

    • Incident Notification & Escalation

    • Investigation and Diagnosis

    • Resolution and Recovery

    • Incident Closure


Incident Management Activities

  • Essential activities include:

    • Review incidents

    • Close incidents

    • Resolve incidents

    • Diagnose and classify incidents

    • Log incidents

    • Detect incidents


1. Incident Identification, Logging, and Categorization

  • Incidents are identified via user reports, analysis, or manual detection.

  • Upon identification, log the incident for categorization and prioritization.


Incident Classification

  • CSIRT classifies incidents as Class A, Class B, or Class C based on risk severity.


Class A Incident: Low Severity

  • Low impact, contained within a unit:

    • No unauthorized disclosure of confidential information.

    • Lost or stolen hardware is of low value.

    • Not mission-critical.

    • Minimal threat potential.

    • Low public interest and minor policy infractions.


Class B Incident: Moderate Severity

  • Moderate impact, contained within a unit:

    • Undetermined unauthorized disclosures.

    • Lost or stolen hardware is of high value.

    • Involves mission-critical services.

    • Possible threat to other IT resources and public interest.


Class C Incident: High Severity

  • Significant impact with potential external effects:

    • Unauthorized disclosure occurred externally.

    • Requires law enforcement involvement.

    • High threat to university resources.

    • Widespread service disruption and potential for public interest.


2. Incident Notification & Escalation

  • Take alerting actions depending on incident type and categorization.

  • Minor incidents may not require formal alerts; escalation is based on categorization.

  • Notify relevant teams, customers, or authorities about the incident.


3. Investigation and Diagnosis

  • Assign staff for investigation of the incident's nature, cause, and solutions.

  • Determine remediation steps after diagnosis.


4. Resolution and Recovery

  • Eliminate threats and restore system functionality.

  • May require multi-stage efforts for severe incidents.

  • Example: In cases of malware, isolate infected components and replace systems.


5. Incident Closure

  • Finalize documentation and evaluate the response actions taken.

  • Identify areas for improvement and preventive measures.

  • Provide reports to administrative teams or customers to maintain transparency.


Ways of Improving Incident Management Process

  • Tips to enhance incident management processes include:


a) Train and Support Employees

  • Training is fundamental for effective incident management.

    • Non-IT staff should know how to report incidents.

    • IT teams must be trained for efficient collaboration.


b) Set Alerts That Matter

  • Avoid alert overload by categorizing events effectively.

    • Define service level indicators to prioritize alerts meaningfully.


c) Prepare Your Team for On-Call

  • Define an on-call schedule to ensure availability of skilled responders.

    • Adjust on-call duties based on past efforts.


d) Establishing Communication Guidelines

  • Create communication guidelines for collaboration.

    • Specify channels, expected content, and documentation practices.

    • Helps mitigate stress during incidents.


e) Update Change Processes

  • Streamline approval processes for necessary changes during incidents.

    • Define levels of changes staff can enact without unnecessary delays.


f) Improve Systems With Lessons Learned

  • Conduct reviews to understand incidents and implement preventive measures.

    • Complete any remaining documentation for audit purposes.


Conclusion

  • Thank you for your attendance!