Ensuring Cyber Security Incident Response Plan Integrates with Cyber Security Policy and Strategy
A cyber security policy and strategy should include:
- the scope of technology and information assets that need to be protected,
- assessment and identified threats to those assets, and
- detail the rules and controls for safeguarding the assets and the business.
An incident response plan is part of the rules and controls for protecting valuable assets.
Cyber Security Incident Response Plan Checklist: Where to Start?
Formulating a CSIRP requires a multi-pronged approach. This checklist should be your primary reference point and be adapted to match your organization's unique landscape. A generic CSIRP, such as NIST’s Incident Handling checklist, can be a good reference point. Still, you must tailor every piece to fit your organization's needs and challenges.
Our trusted Technology Consultants highly recommend seeking an expert to create your custom-fitting CSIRP.
Assessment Phase: Where Are You Now?
Obtain an understanding of the cyber security strategy, policy, and existing incident management process. For example, what tools are in place to monitor for incidents? What is our current incident reporting and documentation process? Who are the individuals that are informed? These are just some of the questions that can help to map out the current state of your incident response process.
Identifying Current Security Measures
Commence by auditing your existing security measures. Your audit is not merely a cursory glance; it involves an exhaustive analysis of the software, hardware, and protocols currently in place. Identify weak links and potential areas of improvement, along with what might or might not be working.
Gap Analysis
Once the existing setup has been cataloged, the next step involves a thorough gap analysis. Scrutinize your security measures vis-a-vis industry best practices to spot vulnerabilities needing immediate attention.
Building Blocks of a CSIRP
Components that Form an Effective Plan
Let's dissect the anatomy of an effective CSIRP. Its core comprises multiple building blocks, each equally critical in formulating a successful incident response strategy.