User:Robbinsm1/sandbox

Topics for SOC-160 class

Evaluating an article
Information security

Content
Overall the article does a good job of presenting Infosec. There are two areas that need to be evaluated, however. The section change management has parts that have been copy pasted. Also, incident response plans need to be further explained.

Tone
The tone of the article is good. It does keep a neutral position and only offers information not opinion. Parts of the article do not have much explanation except for bullet points. It needs to have some of those parts to be expanded.

Talk
Most of the talk page is appropriate conversation around sourcing and minor edits. There are parts of the conversation that have become pandering instead of informational. The article is of importance to the Wikiproject computer science.

Assignment 5
Information security

https://www.iltanet.org/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=966e76a0-5664-43b6-9f3e-fa0540055508&ssopc=1

/sandbox

Incident response plans
Incident response plans are an important part of information security. When the policies in place fail to prevent a security breach, it is important to ensure that a plan is ready to handle the repercussions. It is important to note that there can be legal implications to a data breach. Knowing local and federal laws is critical, and having a lawyer as a member of the team is a best practice. The lawyer can help guide the team around the laws that are in place that have to be followed.

An efficient plan should Include the following :

Preparation
Good preparation includes the development of an Incident Response Team. This team should possess the skills needed to respond to threats if they occur. Some skills need would could be, penetration testing, computer forensics, network security, etc. This team should also keep track of trends in cybersecurity and modern attack strategies. A training program for end users is important as well as most modern attack strategies target users on the network.

Identification
This part of the incident response plan identifies if there was a security event. When an end user reports information or an admin notices irregularities, an investigation is launched. An incident log is a crucial part of this step. All of the members of the team should be updating this log to ensure that information flows as fast as possible. If it has been identified that a security breach has occurred the next step should be activated.

Containment
In this phase, the IRT works to isolate the areas that the breach took place to limit the scope of the security event. During this phase it is important to preserve information forensically so it can be analyzed later in the process. Containment could be as simple as physically containing a server room or as complex as segmenting a network to not allow the spread of a virus.

Eradication
This is where the threat that was identified is removed from the affected systems. This could include using deleting malicious files, terminating compromised accounts, or deleting other components. Some events do not require this step, however it is important to fully understand the event before moving to this step. This will help to ensure that the threat is completely removed.

Recovery
This stage is where the systems are restored back to original operation. This stage could include the recovery of data, changing user access information, or updating firewall rules or policies to prevent a breach in the future. With out executing this step, the system could still be vulnerable to future security threats.

Lessons Learned
In this step information that has been gathered during this process is used to make future decisions on security. This step is crucial to the ensure that future events are prevented. Using this information to further train admins is critical to the process. This step can also be used to process information that is distributed from other entities who have experienced a security event.