{"id":13940,"date":"2021-08-31T17:16:25","date_gmt":"2021-08-31T11:46:25","guid":{"rendered":"http:\/\/ismiletechnologies.com\/?p=13940"},"modified":"2022-12-09T01:01:15","modified_gmt":"2022-12-08T19:31:15","slug":"incident-response-plan-irp","status":"publish","type":"post","link":"https:\/\/ismiletechnologies.com\/en_us\/cloud\/incident-response-plan-irp\/","title":{"rendered":"INCIDENT RESPONSE PLAN (IRP)"},"content":{"rendered":"\r\n<p class=\"wp-block-paragraph\"><strong>RISK MANAGEMENT\u00a0WITHIN SIX PHASES<\/strong>\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>WHAT IS INCIDENT RESPONSE PLAN AND WHY IS IT IMPORTANT?<\/strong>\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Threats\u00a0and danger can never have\u00a0an\u00a0ending and we can\u2019t always avoid them.\u00a0In prehistoric times, when man used to live in caves, he must\u00a0have\u00a0been avoiding the wild beast by lighting fire and hiding in the caves. But what happens if the threat comes in the form of snake, while he is expecting lion or a tiger. We can\u2019t always prepare ourselves from every possible danger and at some point an unknown threat will manifest itself and can leave us injured or worse dead.\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This happens the same way when cyber-criminals attack large organisations\u00a0and leave them with very difficult situation to deal with. Cyber-attacks are planned for various reasons and it only meant to destroy the business internally.\u00a0Internal threats have\u00a0always\u00a0proved to be the most dangerous and\u00a0it is an\u00a0effective strategy for cyber-criminals to plan.\u00a0Within\u00a0the network structure, a malicious actor gets installed through malicious means such as phishing, and it seek out the information it requires or to temporally blocked out the computer system while it do the job of destroying the internal network structure. For financial gain, degrading competition, terrorism and at times for amusement, breaches occur within the organisation. A cyber-attack like that destroys organisational\u00a0reputation, its long developed dignity and exploits its assets to bring\u00a0a halt to its growth and in some cases\u00a0to permanently eradicate the organisation from the competition.\u00a0\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So, if the threat is unavoidable, that doesn\u2019t mean we stop preparing ourselves from such attacks. Rather we need more secure plans and security to protect our organisation from even an unknown threat. So how do we do that? To answer this, let\u2019s take an\u00a0example of an office building where an accident happened\u00a0in the kitchen that leads\u00a0to spreading of fire on the\u00a0entire\u00a0floor. What will be the first\u00a0rescue\u00a0response? Someone might take a fire extinguisher and blow it to the fire or someone buzz the alarm alert that leads to activate the respond system of water sprinklers. What if both of these situations didn\u2019t happen because of unavailability of the first two aids. The fire will keep on spreading until the whole building and the people in it are in tremendous danger.\u00a0Then the fire fighters come on being\u00a0called only in the worst\u00a0of the\u00a0situations, when\u00a0it\u00a0is no longer controllable.\u00a0 This is how our community arranges a hierarchy of risk management. Fire extinguishers and water sprinkles are installed in the building to prepare and to control the fire problem at first glance and if it gets way serious, then we have the number to dial to call the fire rescue team.\u00a0In all the cases, we have aids to protect ourselves and our assets from all kinds of danger\u00a0and early on preparation ensures less danger for the future.\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is how,\u00a0<strong>INCIDENT REPONSE PLAN<\/strong>\u00a0works in organisations\u00a0to rescue the firm\u00a0from internal threats and cyber-attacks.\u00a0It identifies the problem and then\u00a0takes\u00a0necessary measures of response to control the situation and to learn\u00a0from past mistakes, so that it\u00a0would know how to deal with the similar situation in the future.\u00a0\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>An incident response plan is a tested, trained and well-documented technology that works to prevent data and monetary loss and to stop the normal operations in the event of a security breach.<\/strong>\u00a0It is like a digital insurance that every organisation requires in order to make their business safe and secure from cyber-attacks.\u00a0Therefore, it becomes more crucial for all kinds of businesses to take an incident response plan by outside parties, that partnership of digital insurance can diminish the risk of\u00a0future breaches.\u00a0\u00a0<\/p>\r\n\r\n\r\n\t\t<div data-elementor-type=\"section\" data-elementor-id=\"33253\" class=\"elementor elementor-33253\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1f27ef0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1f27ef0\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;gradient&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c65c317\" data-id=\"c65c317\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-dc3c880 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"dc3c880\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-3248be5\" data-id=\"3248be5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5886bd6 elementor-widget elementor-widget-heading\" data-id=\"5886bd6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Ready to experience the full power of cloud technology?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1f56c4e elementor-widget elementor-widget-text-editor\" data-id=\"1f56c4e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun Highlight SCXW216552313 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW216552313 BCX0\">Our cloud experts will speed up cloud deployment, and make your business more efficient.\u00a0<\/span><\/span><span class=\"EOP SCXW216552313 BCX0\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-4b7dd61\" data-id=\"4b7dd61\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-81f081a elementor-align-center elementor-widget elementor-widget-lottie\" data-id=\"81f081a\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;source&quot;:&quot;external_url&quot;,&quot;source_external_url&quot;:{&quot;url&quot;:&quot;https:\\\/\\\/assets4.lottiefiles.com\\\/packages\\\/lf20_kkesf8mx.json&quot;,&quot;is_external&quot;:&quot;&quot;,&quot;nofollow&quot;:&quot;&quot;,&quot;custom_attributes&quot;:&quot;&quot;},&quot;loop&quot;:&quot;yes&quot;,&quot;play_speed&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0.9,&quot;sizes&quot;:[]},&quot;lazyload&quot;:&quot;yes&quot;,&quot;link_to&quot;:&quot;none&quot;,&quot;trigger&quot;:&quot;arriving_to_viewport&quot;,&quot;viewport&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:{&quot;start&quot;:0,&quot;end&quot;:100}},&quot;start_point&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;end_point&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:100,&quot;sizes&quot;:[]},&quot;renderer&quot;:&quot;svg&quot;}\" data-widget_type=\"lottie.default\">\n\t\t\t\t\t<div class=\"e-lottie__container\"><div class=\"e-lottie__animation\"><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-ac6262c\" data-id=\"ac6262c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e19f719 elementor-align-right elementor-mobile-align-left elementor-tablet-align-right elementor-widget elementor-widget-button\" data-id=\"e19f719\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-xs\" href=\"#elementor-action%3Aaction%3Dpopup%3Aopen%26settings%3DeyJpZCI6IjI5OTEiLCJ0b2dnbGUiOnRydWV9\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Start Today !<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>HOW TO CHOOSE THE BEST INCIDENT RESPONSE PLAN FOR YOUR BUSINESS?\u00a0<\/strong>\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">NIST (National Institute of Standards in Technology)\u00a0offers multiple models on which any organisation can choose and use the best IRP model for their business. NIST, a professional body of institution that works in developing better IRP services, guides through their available resources to build a strong Incident response plan for your business, some models are as follows:\u00a0<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>CENTRAL<\/strong>:\u00a0Within the central model of response, a central body of institution handles the response system against cyber-attack such as CSIRT (Computer Security Incident Response Team).\u00a0<\/li>\r\n<li><strong>DISTRIBUTED<\/strong>: In distributed model of response\u00a0system, there are multiple response teams who are responsible to monitor on a specific location or affected area.\u00a0<\/li>\r\n<li><strong>COORDINATED<\/strong>:\u00a0In coordinated model of response system, a specific body of institution is responsible for undertaking and conveying response plan to the affected organisations or businesses.\u00a0\u00a0<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Once you have chosen the best suitable model for your organisation, then it becomes\u00a0way more important to understand\u00a0<em>Incident Response Plan\u2019s six phases<\/em>:-\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>SIX PHASES THAT DETERMINE TO MAKE AN INCIDENT RESPONSE PLAN WORK\u00a0<\/strong>\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">To create an\u00a0incident response plan, make sure that you have addressed carefully and completely the following six phases of IRP:\u00a0<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"569\" class=\"wp-image-13942\" src=\"http:\/\/ismiletechnologies.com\/wp-content\/uploads\/2021\/08\/image-1.jpeg\" alt=\"\" srcset=\"https:\/\/ismiletechnologies.com\/wp-content\/uploads\/2021\/08\/image-1.jpeg 800w, https:\/\/ismiletechnologies.com\/wp-content\/uploads\/2021\/08\/image-1-300x213.jpeg 300w, https:\/\/ismiletechnologies.com\/wp-content\/uploads\/2021\/08\/image-1-768x546.jpeg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/figure>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\">\r\n<li><strong>PREPARATION:\u00a0<\/strong>\u00a0Just like we got\u00a0trained how to respond to fire incident or earthquakes, that kind of drilling and training ensures that more and\u00a0more\u00a0people\u00a0and children\u00a0will know how to deal with such situations, the more\u00a0less\u00a0likely\u00a0that it will affect us in major way. Through training and preparation, we humans have learned that we can wear off any disaster and tackle it with skilled behaviour when an actual event\u00a0occurs.\u00a0<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In the same way,\u00a0a cyber-breach is no less than a natural disaster when it befalls on an organisation. A malware attack takes away all the data, either to destroy the business\u00a0or to use it against. Therefore, planning is the key element to prepare ourselves to learn to tackle with those situations.\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In the preparation phase of the incident response plan,\u00a0keep the following points in mind:-\u00a0<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>Train your employees:<\/strong><strong><em>\u00a0<\/em><\/strong><em>Train your employees in a way that each one knows their roles and responsibilities when an actual breach occurs.<\/em>\u00a0<\/li>\r\n<li><strong>Drill scenarios and mock data breaches:<\/strong><strong><em>\u00a0\u00a0<\/em><\/strong><em>Within organisation, conduct drill scenarios where employees are trained on a regular basis on how to deal with a breach and a mock test will ensure their learning.<\/em>\u00a0<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>Make sure the availability of all the necessary resources<\/strong>:<strong><em>\u00a0<\/em><\/strong><em>Not having the updated software or hardware can result in a breach incident, so it becomes way more important to invest and make available all the resources in advance.<\/em>\u00a0<\/li>\r\n<li><strong>Get approval in advance:<\/strong><strong><em>\u00a0<\/em><\/strong><em>From the main director of the organisation who is responsible for all the execution within the system,\u00a0it is a must for the organisation to get the approval in advance for employees training fund.\u00a0<\/em>\u00a0<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Your response plan<strong>\u00a0<\/strong>should be aiming at maintaining proper documentation and should be tested multiple times to ensure that the employees are ready to perform their key roles and responsibilities during an actual breach incident. The more the employees will get trained; they less\u00a0likely that a breach will occur and it will also aid in maintaining\u00a0the efficiency level of skills in handling a breach situation\u00a0of the organisation as a whole.\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\" start=\"2\">\r\n<li><strong>IDENTIFICATION:\u00a0<\/strong>Identification is the phase where the computer system or experts identify through notifications or disturbances that a malicious actor has been installed within the network system. It alerts the user of its presence and entry point gateway, so that immediate measures will be taken.\u00a0\u00a0<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\" start=\"3\">\r\n<li><strong>CONTAINMENT:\u00a0\u00a0<\/strong>The mistake that is often seen and done during an actual breach is that the user or the employee deletes that data that has been affected. By doing that, the only source of evidence get lost to detect the initial place\u00a0where the malicious host\u00a0got entered.\u00a0Instead, you should contain the breach right there, so that it won\u2019t get spread to damage the business. An organisation ought to have long term and short term strategies ready to deal with the situation. It\u2019s good to have a backup data to help to restore business operations. That way no important information can get lost forever in oblivion.\u00a0<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is good phase in time to update and patch the old systems, to strengthen the requiring authentication identification of each employee in the\u00a0organisation, especially those who\u00a0work remotely through systems of network. It is a good idea to change all the user credentials and passwords harder to guess.\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\" start=\"4\">\r\n<li><strong>ERADICATION:\u00a0<\/strong>Eradication is the time\u00a0to patch up the damage that is made and secure the securities systems harder than ever. In this phase, a thorough analysis should takes place to find out the root cause of the breach and from where it is made. By root cause, we mean finding every inch of the network systems, finding out which applications\u00a0have been\u00a0affected\u00a0and the last but not the least, what tools, tactics and procedures have been employed by the cyber-criminals for the breach.\u00a0\u00a0<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">During this analysis, organisations are supposed to fill out, patch the new vulnerabilities that they discovered during this stage and to get rid of the malware that is affecting the software from within.\u00a0If any trace of a malware in the system remains, the user or the organisation will still be losing essential data which will eventually increase the liability of the business.\u00a0<\/p>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\" start=\"5\">\r\n<li><strong>RECOVERY:\u00a0\u00a0<\/strong>So many questions\u00a0haunt\u00a0us when a malicious\u00a0attack occurs e.g.,\u00a0when can the business be returned to its normal pace? Are the new updated systems being properly patched? Is there another chance of a breach to occur? And so on. That\u2019s\u00a0why, you need\u00a0an\u00a0incident response plan, either you develop your own IRP, or hire a third party to do that for you. In any case, the business needs to return to its former form and restoring, recovering the data that has been lost. This is the phase where the process of restoring and returning the affected systems to its full-fledged form takes place and retaining the business to its previous environment without the fear of being hacked again.\u00a0\u00a0<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\" start=\"6\">\r\n<li><strong>LESSONS LEARNED:\u00a0<\/strong>After the investigation phase, the organisation should keep a meeting with all the incident response team, to discuss the lessons learned from such a breach. A proper RCA\u00a0(Root Cause Analysis) Report should be prepared, wherein all the gathered metrics should be incorporated with updating of new policies and employee training, procedures, plans and tactics\u00a0should tales place.<strong>\u00a0<\/strong>A proper analysis between the drill training and the real cyber-attack incident should form a conclusion of the things where the spot has been missed and what worked and what doesn\u2019t. A proper documentation of the lessons learned will ensure blocking of the similar attacks in the future, whether in the same organisation or the other.\u00a0\u00a0<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>\u00a0<\/strong>As we started our discussion from prehistoric times, why not end it at the same point. We humans are extra-ordinary creatures, who have learned the importance of sharing and learning from other\u2019s mistakes and vulnerabilities\u00a0within our culture. In the cyber-community\u00a0that shared culture is still applicable in 21<sup>st<\/sup>\u00a0century and will continue to be. After a breach incident, the mistakes and learning are shared within our tech-culture, to save some other organisation from the same sort of threat.\u00a0Remaining\u00a0in a healthy competitive market will in fact strengthen us; therefore sharing the lessons learned from a cyber-attack incident is a way of helping each other from meeting the same fate that we are capable of preventing against.\u00a0\u00a0<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>RISK MANAGEMENT\u00a0WITHIN SIX PHASES\u00a0 WHAT IS INCIDENT RESPONSE PLAN AND WHY IS IT IMPORTANT?\u00a0 Threats\u00a0and danger can never have\u00a0an\u00a0ending and we can\u2019t always avoid them.\u00a0In prehistoric times, when man used to live in caves, he must\u00a0have\u00a0been avoiding the wild beast by lighting fire and hiding in the caves. But what happens if the threat comes [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":14273,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[97],"tags":[],"class_list":["post-13940","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud"],"_links":{"self":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/13940","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/comments?post=13940"}],"version-history":[{"count":3,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/13940\/revisions"}],"predecessor-version":[{"id":36072,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/13940\/revisions\/36072"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media\/14273"}],"wp:attachment":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media?parent=13940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/categories?post=13940"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/tags?post=13940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}