ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    incident response plan

    IT Discussion
    5
    10
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Mike DavisM
      Mike Davis
      last edited by

      Can anyone recommend a short incident response plan template? I have a client that is required to have one, and I'm looking for a template is appropriate for a real small firm.

      dbeatoD 1 Reply Last reply Reply Quote 2
      • dbeatoD
        dbeato @Mike Davis
        last edited by

        @mike-davis said in incident response plan:

        Can anyone recommend a short incident response plan template? I have a client that is required to have one, and I'm looking for a template is appropriate for a real small firm.

        Security or Disaster Recovery?

        1 Reply Last reply Reply Quote 1
        • Mike DavisM
          Mike Davis
          last edited by Mike Davis

          Looks like both from their description:

          INCIDENT RESPONSE AND MANAGEMENT
          Protect the organization’s information, as well as its reputation, by developing and implementing an incident response infrastructure (e.g.,plans, defined roles, training, communications, management oversight) for quickly discovering an attack and then effectively containing the damage, eradicating the attacker’s presence, and restoring the integrity of the network and systems.

          dbeatoD 1 Reply Last reply Reply Quote 1
          • dbeatoD
            dbeato @Mike Davis
            last edited by

            @mike-davis said in incident response plan:

            Looks like both from their description:

            INCIDENT RESPONSE AND MANAGEMENT
            Protect the organization’s information, as well as its reputation, by developing and implementing an incident response infrastructure (e.g.,plans, defined roles, training, communications, management oversight) for quickly discovering an attack and then effectively containing the damage, eradicating the attacker’s presence, and restoring the integrity of the network and systems.

            Gotcha, let me look at the ones I wrote for Government agencies.

            1 Reply Last reply Reply Quote 1
            • dbeatoD
              dbeato
              last edited by

              I based it off SANS and NIST
              http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
              https://csrc.nist.gov/csrc/media/publications/sp/800-53/rev-5/draft/documents/sp800-53r5-draft.pdf

              https://www.sans.org/reading-room/whitepapers/incident/incident-handling-process-small-medium-businesses-1791

              https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Downloads/RMH-Chapter-08-Incident-Response.pdf

              Mike DavisM 1 Reply Last reply Reply Quote 0
              • Mike DavisM
                Mike Davis
                last edited by

                Thanks. SANS was the first place I went, but when I looked at that I was like this is crazy for a business that doesn't have any internet facing servers. Only because of other requirements are they even adding a server, but everything is inside their firewall. Their plan on the security side is to call me. Same for the DR side... Maybe for the audit I should just have them attach my business card as "the plan."

                dafyreD 1 Reply Last reply Reply Quote 2
                • Mike DavisM
                  Mike Davis @dbeato
                  last edited by

                  @dbeato said in incident response plan:

                  https://www.sans.org/reading-room/whitepapers/incident/incident-handling-process-small-medium-businesses-1791

                  I missed this one. That fits the bill.

                  1 Reply Last reply Reply Quote 2
                  • dafyreD
                    dafyre @Mike Davis
                    last edited by

                    @mike-davis said in incident response plan:

                    Thanks. SANS was the first place I went, but when I looked at that I was like this is crazy for a business that doesn't have any internet facing servers. Only because of other requirements are they even adding a server, but everything is inside their firewall. Their plan on the security side is to call me. Same for the DR side... Maybe for the audit I should just have them attach my business card as "the plan."

                    "The Plan"... Sounds like the name of a Mafia Hitman.

                    travisdh1T 1 Reply Last reply Reply Quote 1
                    • travisdh1T
                      travisdh1 @dafyre
                      last edited by

                      @dafyre said in incident response plan:

                      @mike-davis said in incident response plan:

                      Thanks. SANS was the first place I went, but when I looked at that I was like this is crazy for a business that doesn't have any internet facing servers. Only because of other requirements are they even adding a server, but everything is inside their firewall. Their plan on the security side is to call me. Same for the DR side... Maybe for the audit I should just have them attach my business card as "the plan."

                      "The Plan"... Sounds like the name of a Mafia Hitman.

                      i can totally see anyone around here piping up with "I AM the plan!"

                      1 Reply Last reply Reply Quote 1
                      • MattSpellerM
                        MattSpeller
                        last edited by

                        https://i.imgur.com/bkuwPrC.png

                        1 Reply Last reply Reply Quote 3
                        • 1 / 1
                        • First post
                          Last post