Participate in Incident Handling

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

35 hours 10 minutes
Video Transcription
Hello and welcome back to Cy Berries. Cop Tear
Certified a van Security practice. Ners certification. Preparation course.
This is, in fact, a continuation off marginal 11 which is title incident with Spun. Let's
here again are the objectives which encompasses this particular module. Let's not turn out to to order the discussion off section to participate in incident handling.
Now let's take a look at the loon objectives and the order in which it would be covered during this particular presentation.
And they are, as follows begin by First are discussing Discovery,
escalation, reporting and feedback loops,
instant response and last but not certainly so which implementation off counter marriages
before we get going with this particular presentation, perhaps, is most appropriate if we will begin by First of all, taking a look at this pre assessment course, too.
And the question is as follows. What is the first step in instant response is a preparation.
Be detection,
See containment, eradication of recovery or D analysis.
The Christmas ball should have been a preparation.
Let's not turn out to tour discussion of an instant response policy.
The response policy is part of the overall Artie security policy for an organization.
In fact, it into a spaz plan is a systematic and documented method of approaching and Manu situation resulting from Artie. Security incidents
or breaches is used in an enterprise I t m vomits and facilities to identify with spawn limit and counteract security incidents as they occur.
The incident was from this policy is in fact, part of the overall Artie security policy for the organization.
It's ah, high level document. That journal includes all aspects of the organization and all geographical location were very large organization that spang globally diverse countries or that includes independent operating units or division. A number and a response policy might be written to address individual locations or
corporate requirements.
This brings us to again taking a look at the very stages which we're gonna take a look at each one of these, ranging from preparation, detection, analysis, containment and eradication of recovery. Then we have post incident activities as well.
Now the National Institutes standard, or NOUS, is the physical size laboratory and a non regulatory agency of United States commerce. Its mission is to promote innovation and industry competitiveness. Now, within the phase of its response, we have the following that preparation, detection, analysis,
containment, eradication, recovery and post incident activity.
The response process has several phases. The initial phase involved establishing and training and
instant response team and acquired the necessary tools on resource is
during preparations. Organization also attempts to limit the number incident that will occur by selecting implement a set of controls
based on the results of a risk assessment. However,
despite your best effort, you're gonna still have incurred what we call residual risk. We continue possessed after controls are implemented. Detection of security breaches dust necessary to alert the organization whenever instance occur.
In keeping with the severity of the incident, those this kid mitigate the impact by containing it
and ultimately recovered from it.
Doing his face activities often cycle back to detection analysis, for example to see a district hosts are infected by mayor. Well, why eradicating the mayor were instant. Athens is adequately handled. Those this incident report that detailed causing and cause of the incident
and a step so they should take to prevent future incidents.
Then we take a look at detection analysis.
First of all, you determine whether instead has occur. You wanna analyze the precursors and indicators look for correlated information. You will perform your research, our search engines. Other words. Employee what we call knowledge base
as soon as a handler believes and has a current
begin the prices of document investigation and gathered the evidence. You wanna prioritize handling the instant based on relevant factors such as a focal impact,
information impact recovery efforts and so forth.
You wanna report incident to the pope, internal personnel and external organization as well.
The next one won't take a look. It's called containment and eradication and recovery.
Containment is an important is important before instant overwhelms, the resource is or increased damage.
Most instances require containment so that in an important consideration early in the course of having each incident,
containment provides time for developing a teller. Remediation of strategy
and a central part of containment is decision making. Other words shut down the system disconnected from my network disabled certain function. Such decisions are much easier to make. If there are predetermined strategies and procedure for containing the incident
orders, they should define acceptable risk in dealing with incidents and develop strategies accordingly.
Then we come to our post incident activities, one of most important pause of an instant response is also most often a minute
learning and improving
each isn't response. Team should evolve to reflect new threats, improved technology and also an improbable we call lessons learnt.
Holding a lesson learned meeting with all involved parties after a major isn't an optional option. In other words, periodically came. Obviously, he can lessen. Instance, as with sources permit and could be extremely helpful. And you improving your security marriages and instant Helen process itself,
multiple incidents can be covered in a single lesson learned meeting. This meeting provides a chance to achieve other words to review what current, what was done to intervene and how well intervention work. That meaning should also be held within days of the enemy incidents and coarse and should be acid doing that process as well.
This brings us to insert response. Planning
in response plan includes identification, off
classification off and response to an incident. Our tax classified it isn't if they are directed against your infamous assets, they have a realistic chance of success.
Could threaten your confident galleon ticket availability of your information resource is and some responses more reactive than proactive. With the exception of planning that must secure to prepare your instant response team to be ready to react to an incident.
Continue on without incident response planning.
You also need to have a policy and that possum was identified a following key components
statement of management, commitment, purpose and objective of the policy scope of the policy. You must also discuss the definition of infinite info, say incidents and related terms.
You also encompasses organization, structure, privatization or severity. Reading of the incidents performance measures, as was reporting and contact forms.
Continue our discussion of instant response planning. When you look, at instance, planning because again planning is everything. If you fail to plan, you plan to fail. So when you look at instant planning,
predefined response is what they do that Abel your organization to react quickly and effectively to Detective Vince. If, for example, though just has an instant response team
and the older guys can detect the incident,
you're in some spots. Team consists of individuals needed to handle systems as incidents take place.
Your instant response plan also has you have to look at the format. The content, the storage as well is testing because no planets good unless of course you have adequately tested the plan.
Isn't Detective Discovery Most common occurrences complained about technology support, often in liver to the help desk?
Careful trainers need to quickly identify and classify the incident. Once the incident's been properly identified, Don's just respond and I'll respond. Nansen indicators may also Barry as well.
Instant reaction consists of actions that got don't they stopped incident, mitigates the impact and provide information for recovery. The action must quickly occur. Other words. You must notify your key personnel. You must also document the incident as well.
Incident containment strategies. Containment of the instant scope or impact as it should be your first priority. It must then determine which in Mrs system obviously didn't affect it.
The owners. This can stop incident an attempt to recover through a number of different strategies
now, before continuing with instant recovery. One since has been contained and call every guy in the next stage. Is recovery
the first task? Identify him resources that it needed launched him into action. The full extent of the damage must also be assessed. Doing that point in time organization repair, it must also engage in the prices of repairing it vulnerabilities address in in your short comments in the safeguard and restore the data and service is off the systems.
They may also be a situation where you need to escalate the incident. The Escalation Mansion involves transferring issue to a higher level management a common example among organization. My existence follow you may have within your internal you have. Your senior management may also have to excavate that escalate that situation.
Too much hard toys, in some
example, will be online and security. You may have some regulatory agencies that you have that that could impact your say. For example, you could be P. C. I, particularly dealing with credit cards. You might also notify or escalate that to the point where you need to look. Notify law enforcement, as was your customers.
Imitation counter marriages. When you think about accounting manager is an action taken, the counter offset. A threat weighing our control may be used in a tech oh prevent a threat.
For instance, a no smoking sign is a control, but a five stinger is in fact a kind of marriages. In other words, kind of medicine go to work after discovery off the threat
in this case countermeasure used to put in the place as a response to a risk analysis. Some examples here being a router, you can master I P address or other words, the Internet protocol address. You're gonna also implore and fires and I spare where application to beget protect against malicious software. You also engage in what we call behavior techniques.
They're applied by users to the tour threats, such as suspicious email attachments.
You have firewalls which again facilitate authorized network access. You can also implore intrusion prevention system as well as detection systems as well.
This brings us to our post assessment question, and the question is as follows
All the following choices. What best weapons at all the steps related to instant response? Is it a preparation, detection, analysis, containment, eradication and recovery?
Or be preparation, containment, detection, analysis,
eradication and recovery, or C containment preparation, detection, analysis, eradication and recovery?
Always IT D containment analysis, detection, eradication and recovery.
If you selected a you absolute correct. It's called preparation, detection,
analysis, containment, eradication and then you have recovery.
Not doing this particular presentation we specifically discuss Discovery
Escalation would also discussed reporter and feedback loops in response and last night. Suddenly so which implementation of countermeasures
and our upcoming topic would be moving on in this particular model, which is getting margin of 11 by taking a look at section number three. We're just tired. I understand and support forensic investigations. Look forward to sitting in the very next video.
Up Next