Question

In: Computer Science

Design a cybersecurity incident response plan for a company, including disaster recovery and business continuity elements...

Design a cybersecurity incident response plan for a company, including disaster recovery and business continuity elements (mitigation strategies and resilience). This should be the detailed plan you wish your organization has in place before a cyber incident or data breach happens in order to effectively respond and limit the cascading effects of the incident and also define the role of a cyber incident report? Who has the responsibility? When the incident has occurred at the bank, what data has been compromised and how the incident occurred? What type of damage it contains and the impacts, any legal implications? Did they restore the business continuity and did they remove the threat? What do you learn from the incident to prevent future attacks? Do you understand what actions worked well and those that did not (Documentation); what to do to improve the organization’s cybersecurity posture; and to keep the management informed and follow proper chain of command procedures?

Solutions

Expert Solution

Answer: See the plan below:

----------------------------------

Introduction:

This document provides the detailed response plan to be adopted by he company in case of a cybersecurity incident. It definces the incident reporting requirements, roles and responsibilities, possible threat scenarios and risks to cyber security, response stratefies, precautionary measures to prevant reoccurring of incidents etc.

Scope:

This plan covers all IT systems, data stores, networks and all associated man power of the company.

Responsibility:

Company's Cybersecurity Emergency Response Team (CERT) has the responsibility to implement, maintain or update this plan. This team is also responsible for detecting, handling and responding to a probable cyber security incident.

Terminology:

Following are the definitions of various terms related to cyber security:

1. Incident: This refers to some event imposing threat to cyber security of the company.

2. Incident Response Process (IRP): It refers to the process to be followed in case of an incident.

Roles and Responsibilities:

Apart from regular security profiles and responsibilities, following roles and responsibilities specific to cyber security incident handling:

1. Incident Response Coordinator: It refers to a person responsible for coordinating the overall process of incident response including data handling and managements, communication with respective stakeholders, incident investigation, status and reporitng etc.

2. Incident Response Manager: It refers to a person who is responsible for collecting, preserving and analysing the evidence of incident.

Approach:

Incident response approach is based on the goal of incident response of reducing the scope of an incident and ensuring the recovery as fast as possible. Overall incident response will be managed in phased manner. Following are major six phases of response:

1. Preparation: Preparation involves carrying out activities that help CERT to handle the response in case of an incident like defining relevant policies, plans, strategies and procedures; deploying required tools and technologies; communication channels etc.

2. Detection: Detection refers to the idenfication, classification and notification of a suspected incident. It is during this phase CERT declares the incident and its severity.

3. Management: This phase refers to identifying the affected resources or systems, isolating or mitigating them, notifying the affected stakeholders in the company and starting investigation.

4. Investigation: It refers to the task carried out by relevant personnel to define the priority, scope and origin of incident.

5. Rectification: Rectification refers to the task to confirming that incident has been manages, notifying affected stakeholders about it and start the recovery of affected resources or systems.

6. Recovery: It refers to normalize the post-incident situation as early as possible, analyze the impact of incident on policies etc., recording the lessons learnt and experiences for future strategies and plans.


Related Solutions

Develop a Incident Response and Business Continuity Planning for Eqauifax
Develop a Incident Response and Business Continuity Planning for Eqauifax
Define and describe disaster recovery and business continuity. Consider and evaluate a business with which you...
Define and describe disaster recovery and business continuity. Consider and evaluate a business with which you are familiar. Discuss potential threats to the business operations and describe ways you would mitigate such risks.
Describe what contingency planning is and how it relates to incident response planning, disaster recovery planning,...
Describe what contingency planning is and how it relates to incident response planning, disaster recovery planning, and business continuity plans
Describe the components of a disaster recovery plan. What role do computer forensics play in a disaster recovery plan?
Describe the components of a disaster recovery plan.What role do computer forensics play in a disaster recovery plan? Summarize the disaster recovery plan you found. What issue does this plan address? Is 3. anything missing?
Is it as important for a small business like JC Consulting to have a disaster recovery plan as
Is it as important for a small business like JC Consulting to have a disaster recovery plan as it is for a large corporation? Please site three different examples to support your position.
Why is important for organizations to have a disaster recovery plan?
Why is important for organizations to have a disaster recovery plan?
Barring the insurance company forcing the organization toundertake a disaster recovery plan, what are two...
Barring the insurance company forcing the organization to undertake a disaster recovery plan, what are two other reasons that may inspire organization to plan for disaster recovery?
A disaster recovery plan (DRP) is a documented process or set of procedures to execute an...
A disaster recovery plan (DRP) is a documented process or set of procedures to execute an organization's disaster recovery processes and recover and protect a business IT infrastructure in the event of a disaster. It is "a comprehensive statement of consistent actions to be taken before, during and after a disaster". Describe a Disaster Recovery Plan (DRP) for Information Technology of a Saudi Business Concern
b. Propose a Disaster Recovery Plan (DRP) to the organization to eliminate the problem in the...
b. Propose a Disaster Recovery Plan (DRP) to the organization to eliminate the problem in the future. [25 marks] Guideline: Google search and download a business continuity plan or DR plan template. DR team, DR servers DR backup. Testing DR monthly. Plan A failure then failover to Plan B.
Explain each of five elements necessary for a disaster plan.
Explain each of five elements necessary for a disaster plan.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT