NIST incident response is the incident response developed in the federal agency' body of cybersecurity guidance to prepare for, manage, and recover from security incident. It gives the organizations with a structured way to organize incident management activities and better respond to computer security events. Incident Detection and Analysis
The incident response process starts with the identification of potential cybersecurity incidents and an assessment of the type, scope, and severity of each incident. Security monitoring alerts system logs, and other sources of information (including reports from end users) may be used to identify suspicious activity.
Analysis can confirm that an event makes up an actual incident and aid response teams with identifying the systems, data, and other resources involved in the incident.
The incident response procedures at NIST center around systematically managing and containing security incidents. When identified an incident response team and activities may include containment, eradication and communication between the response team and the appropriate personnel.
Containment involves stopping the incident from spreading or causing harm and eradication involves removing the threat.
Clear responsibilities and communication channels become critical at this stage. Organizations may put in place incident response teams, escalation mechanisms, documentation needs and commu .
Recovery is concerned with restoring any impacted systems and operations after an incident has been brought under control. Organizations may recover systems from backups, confirm that security concerns have been eliminated and ensure systems are not exhibiting any signs of ongoing or reincurring activity.
Recovery activities should also reflect the operational priorities and business continuity needs of the organization.
Incident response is related to risk management as incidents may expose flaws or gaps in security processes or controls. An organization may use incidents to analyze weaknesses in the security, analyze how well their response was, or assess the need of improved controls.
Experience gained from incidents should be incorporated into new policies and procedures training monitoring capability improvements and response procedures.
Periodic reviews can ensure an organization is continually prepared to respond to emerging technologies, threats and environments. All in all,
nist incident response offers a formalized approach to managing the lifecycle of a cyber security incident from preparedness through to detection response recovery and continuous improvement.
In doing so, although it does not set strict guidelines for incident management, nist approach makes organizations have an idea on how to organize and coordinate incident response activities and improve the organization's overall security and risk management.
Comment