W Hudson Homework 2

.docx

School

Kennesaw State University *

*We aren’t endorsed by this school

Course

7350

Subject

Computer Science

Date

Jan 9, 2024

Type

docx

Pages

4

Uploaded by BaronKnowledge10070

Report
William Hudson CYBR7350 HW # 2 1. Research and identify various incident response (IR) templates/guidelines for organizations. Please list three examples (e.g., NIST, CISA, various private/public organizations, etc.). (15 points) The three incident response plans that I read about are: a. NIST Special Publication 800-61 Rev.2: Computer Security Incident Handling Guide b. CISA National Cyber Incident Response Plan (NCRIP) c. SANS Organization Incident Handling Templates The NIST SP 800-61 Rev.2 publication provides a comprehensive guide for establishing an effective incident response program. It covers various aspects of incident handling, including preparation, detection and analysis, containment, eradication, and recovery (Cichonski, et al. 2012). It is the official incident response guide of the Department of Commerce and is platform, operating system, protocol and application agnostic, making it a versatile tool for any organization to strengthen their incident response processes. The publication details the need for incident response, reviews the basic incident handling steps, advises of the suggested data to collect, provides additional resources that may be helpful when handling an incident, and seeks to provide an overall understanding and methodology that allows organizations to tailor an IR plan that is specific to their unique needs. The National Cyber Incident Response Plan is published by the Department of Homeland Security is designed to be the “strategic framework for operational coordination among federal and SLTT [State, Local, Tribal, Territorial] governments, the private sector, and international partners” (CISA, 2016). It seeks to ensure continuity and approach standardization for all organizations, allowing for a united and organized effort in response to cyber incidents. The NCRIP offers resources that establish a common framework for evaluating the severity of a cyber incident to assist in the communication efforts during a cyber incident. It also provides a guideline on reporting cyber incidents to the federal government, key points of contact, and the roles and responsibilities for federal agencies during a cyber incident. The NCRIP also defines the core capabilities of organizations and provides critical tasks an organization should complete to ensure a strong response to any cyber incident. The SANS Incident Handling Templates are a collection of templates created by and maintained by the SANS Institute, and can be accessed here . Rather than a collection standards and guidelines for creating an IR policy within the organization, the SANS Institute has condensed several specific documents that are meant to be used by incident response personnel to document important information before and during a cyber incident. There are templates to hep responders annotate communications efforts during an incident, templates to help responders determine what key information should be captured, chain of custody logs and other documents that would help responders organize the work they do during the
William Hudson CYBR7350 HW # 2 incident. They are one of the few organizations that specify that the templates they provide are free for use to any business. Their templates appear to be designed for hands-on use by the incident responders rather than a methodology for how to create a plan to respond. 2. Analyze and articulate the differences and similarities between at least two of the templates. (30 points) The NIST SP 800-61 Rev. 2 and NCRIP are very similar in fact that they are both created by governmental entities that seek to help an organization improve their incident response posture by providing methodologies, guidelines, and standards that can be implemented regardless of an organization’s specific hardware, software, or network configurations. They both contain a massive amount of information designed to help all organizations create an IR plan regardless of the organization’s current security posture. They both offer very detailed information about cybersecurity and incident response as a whole and are meant to be used to build out a feasible program. Both documents seek to outline the roles and responsibilities of the different parties that may be involved in a cyber incident, as well as providing information on where to obtain more assistance. There are some tools that can be used to help identify and triage incidents, but these documents are mainly used for an organization to create an IR plan by providing information about the important targets and functions within the organization, offering an outline that should be followed for maximum effectiveness in drafting an IR plan. Conversely, the SANS collection of incident response plans appears to be designed with the front-line incident responder who is actively working the incident in mind. Rather than long- winded explanations of all the things to consider, the SANS collection of documents are specific to different parts of the incident response process, such as chain of custody collection documents, communication logs, and individual system triage forms. The SANS collection assumes that the person using their forms are already versed in information technology and cyber security, whereas a manager without a technical background can build an IR plan using the NIST SP 800-61 Rev 2 and NCRIP. 3. Which template would you recommend for Kennesaw State University and why? (30 points) In cybersecurity, the best defenses are those that have a layered approach. Because of that, I would recommend a combination of these templates to ensure a strong incident response plan for Kennesaw State University. I would recommend using CISA’s NCRIP as the main building block to the IR plan because it provides information specifically to state governments. This is an important distinction versus the NIST SP 800-61 Rev 2 due to KSU being a part of the USG system which receives funding from the state government. The NCRIP goes into great detail on the roles and responsibilities for all governmental entities and provides links to specific agencies to assist in the incident response process. In addition to the NCRIP, I would recommend having
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help