SI311 Grantham Reviewing and Analysing Incident Response Plans Paper Incident Response PlanReview and analysis the provided Incident Response Plan in comparison to what you have read in the Incident Response Planning section of this week’s reading. Attached is an example of the plan.Prepare a 350- to 1,050-word paper that fully discusses the topic questionsFormat your paper consistent with APA guidelines. Format your paper consistent with APA guidelines. Mahtnarg Manufacturing Incident Response Plan
Incident Response Plan
This document discusses the steps taken during an incident response plan. To create the
plan, the steps in the following example should be replaced with contact information and
specific courses of action for your organization.
1) The person who discovers the incident will call the grounds dispatch office. List
possible sources of those who may discover the incident. The known sources
should be provided with a contact procedure and contact list. Sources requiring
contact information may be:
b) Intrusion detection monitoring personnel
c) A system administrator
d) A firewall administrator
e) A business partner
f) A manager
g) The security department or a security person.
h) An outside source.
List all sources and check off whether they have contact information and
procedures. Usually each source would contact one 24/7 reachable entity such as
a grounds security office. Those in the IT department may have different contact
procedures than those outside the IT department.
2) If the person discovering the incident is a member of the IT department or
affected department, they will proceed to step 5.
3) If the person discovering the incident is not a member of the IT department or
affected department, they will call the 24/7 reachable grounds security department
4) The grounds security office will refer to the IT emergency contact list or effected
department contact list and call the designated numbers in order on the list. The
grounds security office will log:
a) The name of the caller.
b) Time of the call.
c) Contact information about the caller.
d) The nature of the incident.
e) What equipment or persons were involved?
f) Location of equipment or persons involved.
g) How the incident was detected.
Mahtnarg Manufacturing Incident Response Plan
h) When the event was first noticed that supported the idea that the incident
5) The IT staff member or affected department staff member who receives the call
(or discovered the incident) will refer to their contact list for both management
personnel to be contacted and incident response members to be contacted. The
staff member will call those designated on the list. The staff member will contact
the incident response manager using both email and phone messages while being
sure other appropriate and backup personnel and designated managers are
contacted. The staff member will log the information received in the same format
as the grounds security office in the previous step. The staff member could
possibly add the following:
a) Is the equipment affected business critical?
b) What is the severity of the potential impact?
c) Name of system being targeted, along with operating system, IP address,
d) IP address and any information about the origin of the attack.
6) Contacted members of the response team will meet or discuss the situation over
the telephone and determine a response strategy.
a) Is the incident real or perceived?
b) Is the incident still in progress?
c) What data or property is threatened and how critical is it?
d) What is the impact on the business should the attack succeed? Minimal,
serious, or critical?
e) What system or systems are targeted, where are they located physically
and on the network?
f) Is the incident inside the trusted network?
g) Is the response urgent?
h) Can the incident be quickly contained?
i) Will the response alert the attacker and do we care?
j) What type of incident is this? Example: virus, worm, intrusion, abuse,
7) An incident ticket will be created. The incident will be categorized into the
highest applicable level of one of the following categories:
a) Category one – A threat to public safety or life.
b) Category two – A threat to sensitive data
c) Category three – A threat to computer systems
d) Category four – A disruption of services
Mahtnarg Manufacturing Incident Response Plan
8) Team members will establish and follow one of the following procedures basing
their response on the incident assessment:
a) Worm response procedure
b) Virus response procedure
c) System failure procedure
d) Active intrusion response procedure – Is critical data at risk?
e) Inactive Intrusion response procedure
f) System abuse procedure
g) Property theft response procedure
h) Website denial of service response procedure
i) Database or file denial of service response procedure
j) Spyware response procedure.
The team may create additional procedures which are not foreseen in this
document. If there is no applicable procedure in place, the team must document
what was done and later establish a procedure for the incident.
9) Team members will use forensic techniques, including reviewing system logs,
looking for gaps in logs, reviewing intrusion detection logs, and interviewing
witnesses and the incident victim to determine how the incident was caused. Only
authorized personnel should be performing interviews or examining evidence, and
the authorized personnel may vary by situation and the organization.
10) Team members will recommend changes to prevent the occurrence from
happening again or infecting other systems.
11) Upon management approval, the changes will be implemented.
12) Team members will restore the affected system(s) to the uninfected state. They
may do any or more of the following:
a) Re-install the affected system(s) from scratch and restore data from
backups if necessary. Preserve evidence before doing this.
b) Make users change passwords if passwords may have been sniffed.
c) Be sure the system has been hardened by turning off or uninstalling
d) Be sure the system is fully patched.
e) Be sure real time virus protection and intrusion detection is running.
f) Be sure the system is logging the correct events and to the proper level.
13) Documentation—the following shall be documented:
a) How the incident was discovered.
b) The category of the incident.
Mahtnarg Manufacturing Incident Response Plan
c) How the incident occurred, whether through email, firewall, etc.
d) Where the attack came from, such as IP addresses and other related
information about the attacker.
e) What the response plan was.
f) What was done in response?
g) Whether the response was effective.
14) Evidence Preservation—make copies of logs, email, and other communication.
Keep lists of witnesses. Keep evidence as long as necessary to complete
prosecution and beyond in case of an appeal.
15) Notify proper external agencies—notify the police and other appropriate agencies
if prosecution of the intruder is possible. List the agencies and contact numbers
16) Assess damage and cost—assess the damage to the organization and estimate both
the damage cost and the cost of the containment efforts.
17) Review response and update policies—plan and take preventative steps so the
intrusion can’t happen again.
a) Consider whether an additional policy could have prevented the intrusion.
b) Consider whether a procedure or policy was not followed which allowed
the intrusion, and then consider what could be changed to ensure that the
procedure or policy is followed in the future.
c) Was the incident response appropriate? How could it be improved?
d) Was every appropriate party informed in a timely manner?
e) Were the incident-response procedures detailed and did they cover the
entire situation? How can they be improved?
f) Have changes been made to prevent a re-infection? Have all systems been
patched, systems locked down, passwords changed, anti-virus updated,
email policies set, etc.?
g) Have changes been made to prevent a new and similar infection?
h) Should any security policies be updated?
i) What lessons have been learned from this experience?
Purchase answer to see full
Why should I choose Homework Writings Pro as my essay writing service?
We Follow Instructions and Give Quality Papers
We are strict in following paper instructions. You are welcome to provide directions to your writer, who will follow it as a law in customizing your paper. Quality is guaranteed! Every paper is carefully checked before delivery. Our writers are professionals and always deliver the highest quality work.
Professional and Experienced Academic Writers
We have a team of professional writers with experience in academic and business writing. Many are native speakers and able to perform any task for which you need help.
Reasonable Prices and Free Unlimited Revisions
Typical student budget? No problem. Affordable rates, generous discounts - the more you order, the more you save. We reward loyalty and welcome new customers. Furthermore, if you think we missed something, please send your order for a free review. You can do this yourself by logging into your personal account or by contacting our support..
Essay Delivered On Time and 100% Money-Back-Guarantee
Your essay will arrive on time, or even before your deadline – even if you request your paper within hours. You won’t be kept waiting, so relax and work on other tasks.We also guatantee a refund in case you decide to cancel your order.
100% Original Essay and Confidentiality
Anti-plagiarism policy. The authenticity of each essay is carefully checked, resulting in truly unique works. Our collaboration is a secret kept safe with us. We only need your email address to send you a unique username and password. We never share personal customer information.
24/7 Customer Support
We recognize that people around the world use our services in different time zones, so we have a support team that is happy to help you use our service. Our writing service has a 24/7 support policy. Contact us and discover all the details that may interest you!
Try it now!
How it works?
Follow these simple steps to get your paper done
Place your order
Fill in the order form and provide all details of your assignment.
Proceed with the payment
Choose the payment system that suits you most.
Receive the final file
Once your paper is ready, we will email it to you.
Our reputation for excellence in providing professional tailor-made essay writing services to students of different academic levels is the best proof of our reliability and quality of service we offer.
When using our academic writing services, you can get help with different types of work including college essays, research articles, writing, essay writing, various academic reports, book reports and so on. Whatever your task, homeworkwritingspro.com has experienced specialists qualified enough to handle it professionally.
Admission Essays & Business Writing Help
An admission essay is an essay or other written statement by a candidate, often a potential student enrolling in a college, university, or graduate school. You can be rest assurred that through our service we will write the best admission essay for you.
Our professional editor will check your grammar to make sure it is free from errors. You can rest assured that we will do our best to provide you with a piece of dignified academic writing. Homeworkwritingpro experts can manage any assignment in any academic field.
If you think your paper could be improved, you can request a review. In this case, your paper will be checked by the writer or assigned to an editor. You can use this option as many times as you see fit. This is free because we want you to be completely satisfied with the service offered.