SANS Incident Response Stages Explained
SANS Incident Response Stages Explained
Thisdocument'smainpurposeistoshowthestagesofanincidentresponsefollowingthe
SANSmethod(SystemAdministration,NetworkingandSecurity)andsomeexamplesofactionstaken
at each step of the treatment. Incident response is any measure taken by a company to
solve and manage security issues, such as data leaks and cyber attacks.
the objective is for this approach to be quick to contain the situation, minimizing costs and
reducing the recovery time from the damages.
PREPARATION REVIEW
The incident response based on the SANS model consists of 6 steps, they are:
1 - Preparation
Train the team to ensure that the incident response works, and that each person
know the functions and actions that must be taken during a security incident.
Weekly meetings for team alignment presenting their functions, plans for
improvements and analysis of reports of preventive and corrective actions taken on clients, in order to
to ensure that all analysts are informed.
Create a documentation model for incident registration containing the history of actions
Actions taken to contain the incident. In order to have it available for consultation.
2 - Identification
Gather as much information as possible with the help of tools, systems, and sources.
reliable, in order to confirm whether the event is an incident and identify what type of attack
it was or is being carried out. Thus, it is necessary to create an action plan for the
threat treatment.
The employee who identifies the incident must inform the immediate supervisor and take action.
The Analyst on Duty, or the incident response team.
Collect and analyze logs using reliable tools such as SIEM, ANALYZER or the
Firewall, server logs.
Validate the threat and identify the type, timing, and origin of the attack.
3 - Containment
4 - Eradication
After discovering the threat, it is necessary to ensure the complete removal of the threat from
affected systems.
Ensure that the root cause has been addressed, thus removing any traces of the threat.
Check whether the attack has affected more than one system or device in the case of WORMS.
5 - Recovery
After tests and validations confirming that the threat has been contained, the systems can be
restored to operational status.
6 - Review
After the security incident is resolved, the incident response team must
ensure that all information that may help in the future is documented.
This includes the maintenance of a comprehensive incident report and the execution of a
post-incident monitoring phase.
Post-incident monitoring, thereby ensuring that the threat has been mitigated and that there is no
no trace of it.
Fill out the report of actions taken to be sent to the client along with
preventive technical recommendations, in order to prevent a future attack.
Final considerations