Sample Incident Response Standard:: Difference between revisions
No edit summary |
|||
(4 intermediate revisions by 3 users not shown) | |||
Line 1: | Line 1: | ||
== | ==Sample Incident Response Standard== | ||
This Incident Response Standard builds on the objectives established in the [[Sample_Threat_Assessment_and_Monitoring_Policy:|'''Threat Assessment and Monitoring Standard''']], and provides specific requirements for developing and exercising formal plans, and associated metrics, for responding to security incidents and intrusions. The Company will satisfy these requirements through a formal Security Incident Response Team (SIRT). | |||
==Objectives== | |||
This Incident Response Standard builds on the objectives established in the [[ | # '''General Requirements''' | ||
## The Company shall develop a SIRT Concept of Operations (CONOP) that: | |||
==''' | ### Summarizes the overall mission of the SIRT | ||
### Defines the SIRT constituents and capabilities | |||
The Company SIRT | ### Defines the SIRT organizational structure | ||
### Defines specific roles and responsibilities of SIRT members | |||
### Summarizes the operational capabilities of the team | |||
## The SIRT, as defined in the CONOP, shall develop plans for responding to expected or typical types of intrusion events, as well as develop contingency plans for responding to new or unanticipated types of intrusions. | |||
## The planned responses shall be dependent on the nature of the intrusion event and the criticality of the potentially impacted Company information assets. | |||
## The SIRT shall maintain awareness of company information asset criticality definitions and shall develop incident response procedures that reflect these definitions. | |||
## The SIRT shall work with other departments as necessary to coordinate, in advance, responses that may directly impact those departments. | |||
## SIRT planning activities shall address the full response spectrum. One end of the spectrum includes information logging as well as personnel notification and alerting. The other end of the spectrum includes higher profile responses (e.g., blocking access to the external web site, denying access from specific external networks, etc.). | |||
## The SIRT shall maintain metrics that address at least the following: | |||
### Incidents detected per reporting period, by severity category | |||
''' | ### Average time from incident detection to response initiation | ||
### Average time from response initiation to incident containment | |||
### SIRT performance during exercises | |||
# '''Response Requirements''' | |||
## A SIRT Incident Response Procedure shall be developed to describe how to: | |||
### Confirm assigned priority for valid incidents. | |||
### Conduct or execute pre-coordinated response plans based on incident category. | |||
### Determine if incidents have been contained. | |||
### Perform basic forensic process to support security investigations. | |||
### Ensure consistent and timely reporting of SIRT response activities. | |||
### Document "lessons learned" to improve SIRT operations. | |||
### Initiate SIRT recovery efforts, if necessary. | |||
## The SIRT shall verify the existence of network and system intrusions, and take actions to contain the threat, in accordance with the SIRT Incident Response Procedure. | |||
## The type of threat activity, together with the criticality of potentially impacted assets, shall provide the direct basis for conducting the incident response. | |||
## SIRT members shall perform their designated, pre-coordinated tasks, in accordance with the SIRT Incident Response Procedure. | |||
## SIRT members shall meet periodically during the incident to check the status and effectiveness of the response. | |||
## The SIRT shall coordinate with or notify impacted departments and external organizations as it conducts the incident response activities. | |||
## The SIRT shall provide Company management with periodic status reports on the response activities. | |||
## The SIRT shall transition to incident recovery activities when the incident or intrusion is contained and meets pre-defined SIRT recovery criteria. | |||
## SIRT incident response capabilities shall be exercised, for evaluation purposes, at least annually. However, the SIRT members (with the possible exception of a senior SIRT manager) shall not be notified in advance of the exercises. | |||
# '''Recovery Requirements''' | |||
## A SIRT Incident Recovery Procedure shall be developed to describe how the SIRT will work within established business resumption and recovery capabilities. | |||
## The SIRT Incident Recovery Procedure shall describe how to: | |||
### Document SIRT damage assessment findings. | |||
### Coordinate with Company departments or teams responsible for recovering impacted systems. | |||
### Ensure consistent and timely reporting of recovery activities performed by the SIRT. | |||
### Document "lessons learned" to improve SIRT operations. | |||
<br> | <br> | ||
== | ==Document Examples== | ||
Use these samples as a guide for your policy development. Fully customizable versions are available from [http://policy-machine.com The Policy Machine].<br> | |||
The | |||
<br> | <br> | ||
<gallery> | |||
Image:Incident Response Standard.png|Incident Response Standard page one of nine. | |||
Image:Incident Response Standard(1).png|Incident Response Standard page two of nine. | |||
Image:Incident Response Standard(2).png|Incident Response Standard page three of nine. | |||
Image:Incident Response Standard(3).png|Incident Response Standard page four of nine. | |||
Image:Incident Response Standard(4).png|Incident Response Standard page five of nine. | |||
Image:Incident Response Standard(5).png|Incident Response Standard page six of nine. | |||
Image:Incident Response Standard(6).png|Incident Response Standard page seven of nine. | |||
Image:Incident Response Standard(7).png|Incident Response Standard page eight of nine. | |||
Image:Incident Response Standard(8).png|Incident Response Standard page nine of nine. | |||
</gallery> |
Latest revision as of 15:24, 21 January 2014
Sample Incident Response Standard
This Incident Response Standard builds on the objectives established in the Threat Assessment and Monitoring Standard, and provides specific requirements for developing and exercising formal plans, and associated metrics, for responding to security incidents and intrusions. The Company will satisfy these requirements through a formal Security Incident Response Team (SIRT).
Objectives
- General Requirements
- The Company shall develop a SIRT Concept of Operations (CONOP) that:
- Summarizes the overall mission of the SIRT
- Defines the SIRT constituents and capabilities
- Defines the SIRT organizational structure
- Defines specific roles and responsibilities of SIRT members
- Summarizes the operational capabilities of the team
- The SIRT, as defined in the CONOP, shall develop plans for responding to expected or typical types of intrusion events, as well as develop contingency plans for responding to new or unanticipated types of intrusions.
- The planned responses shall be dependent on the nature of the intrusion event and the criticality of the potentially impacted Company information assets.
- The SIRT shall maintain awareness of company information asset criticality definitions and shall develop incident response procedures that reflect these definitions.
- The SIRT shall work with other departments as necessary to coordinate, in advance, responses that may directly impact those departments.
- SIRT planning activities shall address the full response spectrum. One end of the spectrum includes information logging as well as personnel notification and alerting. The other end of the spectrum includes higher profile responses (e.g., blocking access to the external web site, denying access from specific external networks, etc.).
- The SIRT shall maintain metrics that address at least the following:
- Incidents detected per reporting period, by severity category
- Average time from incident detection to response initiation
- Average time from response initiation to incident containment
- SIRT performance during exercises
- The Company shall develop a SIRT Concept of Operations (CONOP) that:
- Response Requirements
- A SIRT Incident Response Procedure shall be developed to describe how to:
- Confirm assigned priority for valid incidents.
- Conduct or execute pre-coordinated response plans based on incident category.
- Determine if incidents have been contained.
- Perform basic forensic process to support security investigations.
- Ensure consistent and timely reporting of SIRT response activities.
- Document "lessons learned" to improve SIRT operations.
- Initiate SIRT recovery efforts, if necessary.
- The SIRT shall verify the existence of network and system intrusions, and take actions to contain the threat, in accordance with the SIRT Incident Response Procedure.
- The type of threat activity, together with the criticality of potentially impacted assets, shall provide the direct basis for conducting the incident response.
- SIRT members shall perform their designated, pre-coordinated tasks, in accordance with the SIRT Incident Response Procedure.
- SIRT members shall meet periodically during the incident to check the status and effectiveness of the response.
- The SIRT shall coordinate with or notify impacted departments and external organizations as it conducts the incident response activities.
- The SIRT shall provide Company management with periodic status reports on the response activities.
- The SIRT shall transition to incident recovery activities when the incident or intrusion is contained and meets pre-defined SIRT recovery criteria.
- SIRT incident response capabilities shall be exercised, for evaluation purposes, at least annually. However, the SIRT members (with the possible exception of a senior SIRT manager) shall not be notified in advance of the exercises.
- A SIRT Incident Response Procedure shall be developed to describe how to:
- Recovery Requirements
- A SIRT Incident Recovery Procedure shall be developed to describe how the SIRT will work within established business resumption and recovery capabilities.
- The SIRT Incident Recovery Procedure shall describe how to:
- Document SIRT damage assessment findings.
- Coordinate with Company departments or teams responsible for recovering impacted systems.
- Ensure consistent and timely reporting of recovery activities performed by the SIRT.
- Document "lessons learned" to improve SIRT operations.
Document Examples
Use these samples as a guide for your policy development. Fully customizable versions are available from The Policy Machine.
-
Incident Response Standard page one of nine.
-
Incident Response Standard page two of nine.
-
Incident Response Standard page three of nine.
-
Incident Response Standard page four of nine.
-
Incident Response Standard page five of nine.
-
Incident Response Standard page six of nine.
-
Incident Response Standard page seven of nine.
-
Incident Response Standard page eight of nine.
-
Incident Response Standard page nine of nine.