Lifecycle

table of contents
LIST
FROM [[]]
WHERE parent = this.file.link

IH&R Process Steps

Discussed below are the steps involved in the IH&R process:

Incident Response-1763705225763.webp

Preparation

Step 1: Preparation

The preparation phase includes performing an audit of resources and assets to determine the purpose of security and define the rules, policies, and procedures that drive the IH&R process. It also includes building and training an incident response team, defining incident readiness procedures, and gathering required tools as well as training the employees to secure their systems and accounts.

Detection and Analysis

Step 2: Incident Recording and Assignment

Incident Recording and Assignment

In this phase, the initial reporting and recording of the incident take place. This phase handles identifying an incident and defining proper incident communication plans for the employees and also includes communication methods that involve informing IT support personnel or submitting an appropriate ticket.

Step 3: Triage

In this phase, the identified security incidents are analyzed, validated, categorized, and prioritized. The IH&R team further analyzes the compromised device to find incident details such as the type of attack, its severity, target, impact, and method of propagation, and any vulnerabilities it exploited.

Step 4: Notification

In the notification phase, the IH&R team informs various stakeholders, including management, third-party vendors, and clients, about the identified incident.

Containment, Eradication, and Recovery

Step 5: Containment

This phase helps to prevent the spread of infection to other organizational assets, preventing additional damage.

Example

At 10:30 AM, during routine monitoring, SOC's TIer 1 SOC Analyst Jennifer detects unusual network
traffic and confirms an active [[LockBit]] ransomware infection targeting systems in the
finance department. She escalates the issue to the SOC lead, Sarah, who activates the
Incident Response Team (IRT) and instructs the network team to isolate the finance
department's VLAN to prevent further spread across the network
.

Step 6: Evidence Gathering and Forensic Analysis

In this phase, the IH&R team accumulates all possible evidence related to the incident and submits it to the forensic department for investigation. Forensic analysis of an incident reveals details such as the method of attack, vulnerabilities exploited, security mechanisms averted, network devices infected, and applications compromised.

At Global Tech, a multinational corporation, the SOC team detects a suspicious
[[Ransomware]] outbreak affecting multiple endpoints. After successfully isolating the
infected systems from the network, the [[Digital Forensics]] team, led by Ray Martinez,
begins their investigation. They deploy a forensics workstation to acquire RAM dumps,
extract [[Windows Event Logs]], and collect network [[PCAP]] files from the compromised
hosts.

Step 7: Eradication

In the eradication phase, the IH&R team removes or eliminates the root cause of the incident and closes all the attack vectors to prevent similar incidents in the future.

Step 8: Recovery

After eliminating the causes for the incidents, the IH&R team restores the affected systems, services, resources, and data through recovery. It is the responsibility of the incident response team to ensure that that the incident causes no disruption to the services or business of the organization.

Post-Incident Activity

Step 9: Post-Incident Activities

Once the process is complete, the security incident requires additional review and analysis before closing the matter. Conducting a final review is an important step in the IH&R process that includes:

  • Incident documentation
  • Incident impact assessment
  • Reviewing and revising policies