Discovering your network has a breach is bad enough. Having to develop your response on the fly is even worse. In its November 2013 Data Breach Investigations Report, Verizon Enterprise investigated over 47,000 security incidents including 621 confirmed data breaches. Two-thirds of the data breaches in the report took either months or years to discover.
According to an analysis by the Ponemon Institute, having a strong security posture including cloud security solutions is the best way to curb the financial fallout from a data breach. Having an incident response plan in place was the second most influential factor in reducing the costs of data breaches. Many incident response plans fail to coordinate incident response across multiple departments and, in global organizations, across multiple countries and business segments. Many companies rely on one or two “go-to” persons who may be unavailable at a critical momentor unequipped to manage a large-scale incident. Some organizations have a plan written down, but the plan may be out-of-date or too generic. When evaluating the state of incident response at your organization, follow these guidelines.
Identify What’s Valuable
Depending on your organization, your incident response plan will include different security mandates. If you’re part of a healthcare organization, for example, then HIPAA and HITECH mandates could mean stiff financial penalties. In fact, Ponemon discovered that heavily regulated industries like healthcare, financial services, transportation and communications all incurred data breach costs that were significantly above the median. For this reason, IT should start developing any incident response plan by identifying the organization’s most crucial data assets including customer/patient information and intellectual property. Regulatory requirements will play a crucial role in determining the value of data assets.
Develop a Plan
One of the biggest incident response failures is having a plan in place that is too generic. Follow these steps to create a plan that’s specific and easy to activate:
- Develop customized responses according to security incident and data value. The National Institute of Standards and Technology identifies four broad categories of security incidents: unauthorized access, malicious code, denial of service and inappropriate usage. Develop protocols for each type of incident.Develop a second set of protocols classified by the type of data involved.
- Decide what to do.Specific responses should include team structures, individual roles and responsibilities, war rooms and escalation thresholds. Distribute quick response guides and include a specific call chain. Identify who has the authority to make which decisions, such as who makes the decision on whether or not to inform law enforcement.
- Short-term recovery. Develop short-term recovery steps. For example, a short-term solution could include isolating applications or network components, or it could include moving network operations offsite.
- Long-term recovery. During this phase, plan for how IT should reconstitute operations. Ensure adequate infrastructure, reinstall system components, test them and back up all operational data at the contingency site before shutting it down. Other parts of the organization, like Legal and PR, should be dealing with the fiduciary and branding fallout from the incident.
- Make a better plan if needed. Identify forensic steps for improving incident response after a security breach occurs.
Rehearse and Identify Gaps
Coordinate with other departments and branches to rehearse incident response as needed. For example, set up a quarterly fake security breach and see how effectively everyone works. Rehearsal will tell youabout knowledge gaps and resource gaps throughout the organization. Create training opportunities and redistribute resources as needed. Then, rehearse again until incident response becomes instinctive.
Get Executive Buy-in
Cyber security needs to be a priority in the C-suite as well as in IT. In an ideal situation, the organization should have an executive devoted to security, such as a chief information security officer (CISO) charged with organizational data protection. The C-suite will have to take an active role in deciding how much to tell the public, when to tell the public, how to assess financial fallout and how to report the incident to the appropriate regulatory and law enforcement authorities. More than anything, IT needs executives to cheerlead their efforts to develop an incident response plan. Executive support can motivate everyone in the organization to take ownership of incident response.
Author: Karen Monahan works as a network security consultant.
Mostly Blog Mostly Blog shares latest news and review of Apple iPhone, Google Nexus, Micromax, HP, Nokia, Apple IPad, Android Phones, jailbreak IOS, iphone apps, unlock iphone, download jailbreak, iphone accessories.
