Hello. My name is David Visor and welcome to post Incident Response. Welcome back. Incident handling. It's in that handlers, everyone guards out, kind of like being a dog in front on and in some ways, that's what it is. But dealing with people and with
data and your equipment is we are going to be talking about documentation.
Ah, not a popular topic. Nobody likes paperwork on the same way, but
we live in a world where you can't escape. Um, I grew up in a world with a lot of paper pre digital age, a CZ you remember me mentioning earlier. I am going on. No, guys, I hear, um,
but documentation, whether it's not digitally, whether it's done on paper in a notebook ir a ver informed whenever is extremely important to the incident handling process, I am one of
the biggest ones is your plan your response plan. But there are tons of other plans out there
other ways to document things that were going on. You have a distant response. Forensic report. You could have a mountain where, uh, analysis report. You can have reports
from system admin is exchange and men's. You could have service now tickets and included as part of your report that you could see your building your documentation on coming out of law enforcement.
One of the big things that we learned was document document document. If it's not written down somewhere, then it technically did not happen.
Ah, and auditors are big on that, too. So I don't think that's just some stupid lone horse. That thing for an auditor of other times, if they can't see it on a piece of paper in front of them on the screen in front of them than to them, it was a non issue. It never happened. So when it comes to visit me as a witness, that response
documentation is extremely important. When it comes to an incident, a breach, it's extremely important to follow your documentation. It's not time to go the way of a while. Last in just start shooting. In all their actions,
it's time to follow the
when the auditors will ask about that, inspectors will ask about that. They may very well sit down and look at your incident response documentation,
something that happened like during the incident. Let's say
then they're going to look back at your response plan and see if you actually follow it. If you didn't, you could very well contained by them because you failed, not aspect, not be on it. I have seen that happen in the real world. Some auditors
having particular about those kinds of things. So what we need to do is focus on documentation for a few minutes. Here together,
you have reports, processes, procedures. You have e mails
again. Not only new auditors check these things out, but civil liability could come into play as well. Um,
I've used examples from court testimony and things like that in some prior episode side of really one of 42 years of this kind of things. But I do need to stress it with you that this is important to remember.
E mails can be vital. Uh, one email sent from an incident response analyst to a system admin providing them of indicators compromised. To add to, say, an I. D. S or nine P s. And then during the follow up period, the after action
it's order that there's indicators compromise work at it.
the i. D. S. R I. P s. Well, then it becomes a, uh, battle of words system admin saying on that email the incident response analyst saying, I know I sent it to you. But the response analysts deleted, it has a record of it,
and things get uncomfortable very quickly.
Sue, if you're in the middle of an instant document document talking way, talk about the incident response plan on There are,
I want to say, hundreds, but it's probably not hundreds, but there's at these dozens of templates out there on the Internet that you could do searches for on, download on and utilize to draft your own. That they all want to warn you about here is that don't be that person.
The download's a template.
So after a company logo on and says, This is our incident response plan that you throw in the folder a binder. It was in your desk. And when the n. C. U A. Auditors come in and their asking clearances response plan, that's what you get up. It's ridiculous on its foolish,
but that's what I see many, many times out in the real world. That's how
nontechnical people address this issue
you as the expert, the subject matter expert. Did she harass sitting? I can't afford to allow that kind of thing happen. So why wants to do in this episode is actually take a look at the computer security and responsible. Now, this is just one template.
I'm actually gonna let this onto our
course so that if he wanted you came down with it, he can adapt it and take it and use it again. I'm gonna warn you here. Don't just slap your logo on it and say this is it personalized and build it the right way.
These could be a CZ complex or as non compliant. Did you want to make them?
I find that they need to be fairly detailed in order to
actually be adequate and useful in the real World Document history section. Basically thes things. Thes reports. These plans should be updated in multiple ways after every incident, but they should be reviewed and updated,
Uh, at least annually. If there's no incident in the year, then you should be reviewed and updated because guess what? The cyberworld is always changed.
New attacks, new protected measures. Um,
new person now being assigned to your team are hired by the company come into play, so at least annually on it definitely should be done after each incident. It should be reviewed. And then you document there's refusing updates underneath the document History section right here.
That way you have a record of when you document it and hate it.
Then you need some signatures because this is basically you're irritated. Clean. This is the decree from the King that is giving the lower beings in the field
the authority to do certain things. If you remember back a few episodes we talked about who has the authorities on blood system to shut down a lead to
restore database. This is where that comes from. Eso you have some signatures here and depending upon how they're titled in your company Corsi and managers or whoever made Britain, then the really important ones Would that be in your director level?
remount the lineup right? Or you're CIS set should sign off on this. These approval signatures are important. In order to grant the proper authority and power to your incident responders who are going to be asking for things like shut down the X Games over.
Shut down that database, turn off all access to it.
It could cost your business money. It could cause business continuity churches. And if the authority isn't provided in a written format, then people are gonna be saying, Whoa, you don't have the authority to tell me to do that. I'm not. Do that. Remember our last episode? I said the incident manager was a playground monitor.
That's where that comes into play.
So you can write this up in a number of different ways. Is always an introduction, sort of setting the stage, providing the objectives of the plans that everybody that reads it knows what is going to be covered in the plan You definitely need to do. And it's that roles and responsibilities and identify who is the c cert
mister we needed. Whether it's this is so our vice president or director, the incident manage one of the most important roles during an incident needs to be identified here so that whoever is gonna put people in that position, those they have before you, of course, the document, our management team
and then the proceed response procedure, which should be followed on these can be taken and updated every once you have got deeper and there's a Mrs Brad old. But, hey, some companies do you still use beepers
identifying all the different steps that need to be followed to again? Take this adapted to your use, um,
and whatever way and method that you need and whatever index is you need. So we have some passed within the incident response life cycle which has been identified. We've seen these before preparation, detection, analysis, containment,
eradication and recovery. And then finally, lessons learned on DDE
so you can adapt these however you want
regards. Analysis is important when it comes to an incident.
And then you have rolls again laid out What responsible work
again. This is gonna be up on the course website so that you can download this you it actually will and pleasure andan adapted to the use that you find necessary. Port
Dr Quick in production Thio Incident documentation Theo Any questions And then maybe 135 Be happy to talk to you on separate. Have a great day