4.8 Explain Appropriate Incident Response Activities

  • Effective incident response is governed by formal policies and procedures.

  • Policies and procedures delineate roles and responsibilities for the incident response team.

  • Importance of adherence to assigned roles within the incident response team for optimal effectiveness.

Understanding Cybersecurity Incidents

  • Definition of a Cybersecurity Incident:

    • Refers to a successful or attempted violation of security properties of an asset.

    • Compromises confidentiality, integrity, or availability of that asset.

  • Incident Response (IR) Policy:

    • Establishes resources, processes, and guidelines for addressing cybersecurity incidents.

    • Requires each incident to be managed following a process lifecycle.

CompTIA's Incident Response Lifecycle

  • Seven-Step Incident Response Process:

    1. Preparation:

    • Involves measures to enhance system resilience against attacks.

    • Actions include hardening systems, creating policies, and securing communication lines.

    • Development of incident response resources and procedures.

    1. Detection:

    • Activity involves identifying indicators of threat actor activity.

    • Detection can be automated via intrusion detection systems or by manual threat hunting.

    • Reports can originate from employees, customers, or law enforcement.

    1. Analysis:

    • Determines if an incident occurred and assesses its severity through triage methods.

    1. Containment:

    • Limits scope and magnitude of the incident to secure data.

    • Involves notifying stakeholders and fulfilling reporting requirements.

    1. Eradication:

    • Removal of the cause and restoration of affected systems to a secure state.

    • May require applying secure configurations and installing patches.

    1. Recovery:

    • Reintegration of the system back into business processes post-eradication.

    • Might include restoring data from backups and continual monitoring for attacks.

    1. Lessons Learned:

    • Analyzes incidents and responses to improve future procedures.

    • Importance of documentation for feedback mechanisms to enhance preparation processes.

Incident Response Coordination

  • Complexity of Incident Response:

    • Multiple departments or managers might need to coordinate during incident response.

    • Phases are specifically focused on cybersecurity incidents, separate from major incidents managed by disaster recovery processes.

Preparation for Incident Response

  • Establishing Policies and Procedures:

    • Continuous updates and management of policies for security breaches.

    • Provisioning personnel and resources essential for incident management.

  • Cybersecurity Infrastructure Components:

    • Incident Detection Tools:

    • Automate the collection and analysis of network traffic, system state, and logs.

    • Digital Forensics Tools:

    • Assist in acquiring and validating data from system memory and file systems for evidence or prosecution.

    • Case Management Tools:

    • Facilitate logging of incident details and coordination among team responders.

    • Often implemented as a product suite including SIEM and SOAR for alerting and monitoring.

Cyber Incident Response Team (CIRT)

  • Team Composition:

    • Composed of members with diverse security competencies (CIRT, CSIRT, CERT).

    • Teams may operate within a Security Operations Center (SOC).

    • Leadership: Senior executive responsible for authorization following serious incidents.

    • Roles within the Team:

    • Managers: Oversee daily operations and coordinate responses with other departments.

    • Analysts and Technicians: Handle minor incidents independently and prioritize cases.

  • Collaboration with Other Departments:

    • Legal: Ensures compliance with laws and regulations, liaises with law enforcement.

    • Human Resources (HR): Addresses employment impacts relating to incidents, underlying issues.

    • Public Relations: Manages public perception and external communications around incidents.

Communication in Incident Response

  • Critical Elements of Incident Communication:

    • Prevent unauthorized information release and manage adversary awareness.

    • Use of a formal Incident Response Plan (IRP) listing procedures, contacts, and resources.

  • Communication Plan Essentials:

    • Establish clear lines for reporting incidents and notifying involved parties.

    • Essential contact information and use of out-of-band communication methods.

  • Stakeholder Management:

    • Importance of controlled dissemination of incident details to avoid panic or misinformation.

    • Obligation to report incidents to affected parties and regulatory bodies.

Detection of Cybersecurity Incidents

  • Detection Process:

    • Correlating events from various data sources to detect indicators of an incident.

  • Sources of Detection Indicators:

    • Anomalies in log files, IDS alerts, error messages, manual site inspections, employee reports, and external threat reports.

    • Encourage confidential reporting mechanisms for employees to report threats without fear.

  • Role of First Responder:

    • Critical to notify the appropriate team member to take charge upon detection of suspicious events.

Analysis of Detected Incidents

  • First Responder Investigation:

    • Determine whether a genuine incident has occurred and assign priority.

    • Classify incidents as true positives or false positives based on correlating indicators.

  • Impact Determination Factors:

    • Data Integrity: Considered the top priority based on the value of at-risk data.

    • Downtime: Evaluates incident disruptions—whether it degrades or interrupts availability.

    • Economic/Publicity Considerations: Assess immediate and long-term costs of the incident.

    • Scope: Number of affected systems as it relates to incident priority.

    • Detection and Recovery Times: Need for prompt detection and effective recovery measures.

  • Incident Category and Definitions:

    • Shared understanding of terms among response team members critical for effectiveness and effective use of threat intelligence.