Home > Information Security News > Firms muddle security breach response, expert says
Information Security News:
EMAIL THIS

Firms muddle security breach response, expert says

By Robert Westervelt, News Editor
18 Mar 2009 | SearchSecurity.co.uk

Security UK News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Most security breach responses are poorly coordinated despite advance planning, warns a security expert researching ways to improve security investigations and incident response procedures.

Stress and lack of a clear leader are among the biggest problems that plague security incident response, said security expert Lenny Zeltser, a consultant and member of the SANS Institute board of directors. Zeltser presented his research last week at the SOURCE Boston security conference.

"When people are under stress mistakes are made," Zeltser said. "Someone needs to assert authority and in most cases that should lie with the incident handler."

But asserting authority doesn't mean barking orders at people, Zeltser said. The handler should get to know the response team members and their roles at the company. Ask questions to get a better understanding of the system and data owners. Assign roles and assign people to communicate with different groups in the company. Those people should give updates to employees hourly at the onset of an incident, even if there is nothing to update.

"Update them because it keeps them calm and gives them a sense that you're working diligently on the incident," Zeltser said.

High profile data security breaches have prompted company officials to ensure incident response procedures are in place and an effective plan is available to use as a guide during a crisis. But Zeltser explained that some firms haven't dusted off their incident response procedures in years and others are relying on common procedures that aren't specific enough to their line of business.

Even the best procedures fail to overcome the stresses involved in the initial throes of a breach. Get a handle on how data flows through the company systems to assess the scope of the security incident. Zeltser said. The technical stage of incident response is often where incidents get muddled. Don't assume people know what to do next. Also, consider the tools and data sources available before deciding whether to conduct live analysis or formal forensics.

Assign an incident response team member to consult with the legal team or the company's legal counsel, he said. Find out who has the authority to make decisions that could affect the company's overall business, such as pulling a critical system offline.

During the presentation, Zeltser also handed out a security incident questionnaire for responders and a cheat sheet for server administrators examining a suspected breached server to decide whether to initiate a formal incident response.

Six key security incident response steps:

  • Preparation: Gather and learn the necessary tools and become familiar with your environment.
  • Identification: Detect the incident, determine its scope and involve the appropriate parties.
  • Containment: Minimize the incident's effect on neighboring IT resources.
  • Eradication: Eliminate compromise artifacts, if necessary, on the path to recovery.
  • Recovery: Restore the system to normal operations, possibly via reinstall or backup.
  • Wrap-up: Document the incident's details, recall collected data and discuss lessons learned.

Incident response in an organization is usually coordinated by a person who is from IT or was technical at one time, Zeltser said. But in many cases, organizations treat incident response as a technical problem and fail to focus on communicating clearly or following sound processes.

"They focus their efforts on making sure the right tools are in place, the right hardware and software is procured; that the right steps are documented on how to clone a hard drive or examine memory contents," Zeltser said. "They don't pay enough attention to the human and process side of things."



Tags: Data Breach Incident Management and RecoveryVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Data Breach Incident Management and Recovery
Make PCI DSS compliance easier by reducing scope, outsourcing data
Full disk encryption: Safer and easier than file and folder encryption
PCI DSS requirements: Get ready for stricter enforcement, fines
Data breach costs continue to rise in 2009, Ponemon study finds
Data Protection Act breach could cost companies 500,000 pounds
Jericho Forum to provide customers with good security questions to ask
Verizon report goes deep inside data breach investigations
Insider threat detection still a challenge for employers
Layoffs prompt insider threat fears, cybersecurity survey finds
ArcSight boosts system log management capabilities

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



IT Solutions for the UK: Data Security, Network Security, Application Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts