Incident Response Plan - Part 1: Incident Identification, Detection and Analysis You have been chartered with documenting your company’s Incident Response Plan. The first portion of the plan must...

1 answer below »


Incident Response Plan - Part 1:






Incident Identification, Detection and Analysis


You have been chartered with documenting your company’s Incident Response Plan. The first portion of the plan must address Preparation, Detection and Analysis. Whilean organization's Incident Response Plan would normallyaddress many types of incidents, for the purposes of this assignment you will only be preparing a short report with respect to a single type of incident.


Select an incident scenario of your choosing. Using industry level guidance such as the NIST Computer Security Incident Handling Guide (800-61) for guidance, prepare a short report that answers the following questions. The sections referred to are in the NIST document.



Preparation:


1. Would the organization consider this activity to be an incident? If so, which of the organization’s policies does this activity violate?


2. What measures are in place to attempt to prevent this type of incident from occurring or to limit its impact?



Detection and Analysis:


1. What precursors of the incident, if any, might the organization detect? Would any precursors cause the organization to attempt to take action before the incident occurred?


2. What indications of the incident might the organization detect? Which indications would cause someone to think that an incident might have occurred?


3. How would the incident response team analyze and validate this incident?


4. To which people and groups within the organization would the team report the incident?


5. How would the incident response team prioritize the handling of this incident?


Answered 4 days AfterOct 22, 2021

Answer To: Incident Response Plan - Part 1: Incident Identification, Detection and Analysis You have been...

Deepti answered on Oct 26 2021
118 Votes
Employees in my organization have been granted access to resources according to their job profiles so that they can complete their work. Administrator grants all the employees, the access rights as per their role in accordance with the organization’s policies.
The incident response plan addressed in this report is for privilege abuse. Certain employees were given privilege to access resources and data that were crucial to the security of the organization and its business. The organization shall consider it as an incident since poor access control allowed the users more access rights than they needed to complete their jobs. The administrator granted access rights to two employees and they were able to access protected information of customers. There was poor understanding of what users are doing in critical systems and how they were interacting with sensitive data. Access was given to users who did not require that data for their work. It was discovered during a routine audit of access logs. Access control issue stemmed from lack of understanding between IT management and security team. The employees who knowingly or...
SOLUTION.PDF

Answer To This Question Is Available To Download

Related Questions & Answers

More Questions »

Submit New Assignment

Copy and Paste Your Assignment Here