Lecture 7 Incident Response
Incident Response Lecture 7
What is an Incident?
A computer security incident is any action or activity—accidental or deliberate—that compromises the confidentiality, integrity, or availability of data and IT resources.
Includes activities such as:
Fraud
Child pornography
Theft
Hacking
Policy violations may also be considered security incidents.
Incident Response Plan (IRP)
An IRP ensures the right personnel and procedures are in place for effectively handling security breaches as they occur.
Provides a targeted response to contain and remove threats.
Backup Data: Identify and back up critical data in a remote location (like the cloud).
Prioritization of backups is crucial.
Employees must understand their roles during a cyber incident for quick recovery.
Team Leadership and Duties
CISO or Operations Team Lead typically acts as the CSIRT Leader.
Tasks include:
Convene the CSIRT (Computer Security Incident Response Team)
Select additional support members as necessary
Contact the Chief Information Officer (CIO)
Conduct and document meetings
Manage incidents and ensure proper documentation
Report status to the CIO
Train team continuously
Conduct debriefings and report lessons learned
Team Expertise
Various team members may be involved such as:
Registrar
Public Information Officer
Platform Specialists
Financial Administrators
Law Enforcement
CIO
Chief Auditor Office
Legal
Human Resources
Information Security (CISO or Representative)
Incident Response Goals
Preserve the confidentiality, integrity, and availability of enterprise information.
Minimize organizational impact.
Provide management with pertinent information for decision-making.
Ensure a structured, logical, repeatable, and successful approach to incidents.
Improve efficiency and effectiveness of incident management.
Mitigate financial and human resource impacts.
Gather evidence for potential legal and liability issues.
Incident Models
Utilize predefined incident models to handle recurring incidents effectively.
Necessary components of the model:
Steps in chronological order for incident handling.
Defined responsibilities for team members.
Timelines for action completion.
Escalation procedures.
Evidence preservation activities.
Incident Management Process
The process consists of:
Incident Identification, Logging, and Categorization
Incident Notification & Escalation
Investigation and Diagnosis
Resolution and Recovery
Incident Closure
Incident Management Activities
Essential activities include:
Review incidents
Close incidents
Resolve incidents
Diagnose and classify incidents
Log incidents
Detect incidents
1. Incident Identification, Logging, and Categorization
Incidents are identified via user reports, analysis, or manual detection.
Upon identification, log the incident for categorization and prioritization.
Incident Classification
CSIRT classifies incidents as Class A, Class B, or Class C based on risk severity.
Class A Incident: Low Severity
Low impact, contained within a unit:
No unauthorized disclosure of confidential information.
Lost or stolen hardware is of low value.
Not mission-critical.
Minimal threat potential.
Low public interest and minor policy infractions.
Class B Incident: Moderate Severity
Moderate impact, contained within a unit:
Undetermined unauthorized disclosures.
Lost or stolen hardware is of high value.
Involves mission-critical services.
Possible threat to other IT resources and public interest.
Class C Incident: High Severity
Significant impact with potential external effects:
Unauthorized disclosure occurred externally.
Requires law enforcement involvement.
High threat to university resources.
Widespread service disruption and potential for public interest.
2. Incident Notification & Escalation
Take alerting actions depending on incident type and categorization.
Minor incidents may not require formal alerts; escalation is based on categorization.
Notify relevant teams, customers, or authorities about the incident.
3. Investigation and Diagnosis
Assign staff for investigation of the incident's nature, cause, and solutions.
Determine remediation steps after diagnosis.
4. Resolution and Recovery
Eliminate threats and restore system functionality.
May require multi-stage efforts for severe incidents.
Example: In cases of malware, isolate infected components and replace systems.
5. Incident Closure
Finalize documentation and evaluate the response actions taken.
Identify areas for improvement and preventive measures.
Provide reports to administrative teams or customers to maintain transparency.
Ways of Improving Incident Management Process
Tips to enhance incident management processes include:
a) Train and Support Employees
Training is fundamental for effective incident management.
Non-IT staff should know how to report incidents.
IT teams must be trained for efficient collaboration.
b) Set Alerts That Matter
Avoid alert overload by categorizing events effectively.
Define service level indicators to prioritize alerts meaningfully.
c) Prepare Your Team for On-Call
Define an on-call schedule to ensure availability of skilled responders.
Adjust on-call duties based on past efforts.
d) Establishing Communication Guidelines
Create communication guidelines for collaboration.
Specify channels, expected content, and documentation practices.
Helps mitigate stress during incidents.
e) Update Change Processes
Streamline approval processes for necessary changes during incidents.
Define levels of changes staff can enact without unnecessary delays.
f) Improve Systems With Lessons Learned
Conduct reviews to understand incidents and implement preventive measures.
Complete any remaining documentation for audit purposes.
Conclusion
Thank you for your attendance!