0% found this document useful (0 votes)
26 views3 pages

SANS Incident Response Stages Explained

This document describes the steps for responding to security incidents according to the SANS method, including preparation, identification, containment, eradication, recovery, and review. Incident response aims to quickly resolve and manage security issues to minimize costs and reduce recovery time.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
26 views3 pages

SANS Incident Response Stages Explained

This document describes the steps for responding to security incidents according to the SANS method, including preparation, identification, containment, eradication, recovery, and review. Incident response aims to quickly resolve and manage security issues to minimize costs and reduce recovery time.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INCIDENTRESPONSE

Thisdocument'smainpurposeistoshowthestagesofanincidentresponsefollowingthe
SANSmethod(SystemAdministration,NetworkingandSecurity)andsomeexamplesofactionstaken
at each step of the treatment. Incident response is any measure taken by a company to
solve and manage security issues, such as data leaks and cyber attacks.
the objective is for this approach to be quick to contain the situation, minimizing costs and
reducing the recovery time from the damages.

Incident Response Flow

IDENTIFICATION CONTAINMENT ERADICATION RECOVERY

PREPARATION REVIEW

The incident response based on the SANS model consists of 6 steps, they are:

1- Preparação, 2- Identificação, 3- Contenção, 4- Erradicação, 5- Recuperação, 6- Revisão.

1 - Preparation

Train the team to ensure that the incident response works, and that each person
know the functions and actions that must be taken during a security incident.

Monthly training with laboratories and simulated real attack situations in


controlled environment helps the team understand the scenario and know how it will be handled
real incident case happens.

Weekly meetings for team alignment presenting their functions, plans for
improvements and analysis of reports of preventive and corrective actions taken on clients, in order to
to ensure that all analysts are informed.

Create a documentation model for incident registration containing the history of actions
Actions taken to contain the incident. In order to have it available for consultation.

2 - Identification

Gather as much information as possible with the help of tools, systems, and sources.
reliable, in order to confirm whether the event is an incident and identify what type of attack
it was or is being carried out. Thus, it is necessary to create an action plan for the
threat treatment.

The employee who identifies the incident must inform the immediate supervisor and take action.
The Analyst on Duty, or the incident response team.

Collect and analyze logs using reliable tools such as SIEM, ANALYZER or the
Firewall, server logs.

Validate the threat and identify the type, timing, and origin of the attack.

Create or follow an action plan containing actions to be taken, communication room,


planning and responsible for each detail, communication with the client to inform
the seriousness of the incident and set deadlines for follow-ups regarding the occurrence and the status.

3 - Containment

Short-term reactive actions to isolate the threat or malicious agent, avoiding


that may even affect other systems, or a coordinated shutdown of the devices or
affected systems.

Coordinated shutdown of affected devices or systems in order to isolate the threat


or the malicious agent, to prevent it from spreading in the network.

Blocking access to the network or systems, malicious IPs, neutralizing backdoors,


close external connections, divert requests using a blackhole strategy
routing ou modificar as configurações de protocolos de rede.

Cleaning malicious files using antivirus or inspection tools


files or sandbox.

4 - Eradication

After discovering the threat, it is necessary to ensure the complete removal of the threat from
affected systems.

Ensure that the root cause has been addressed, thus removing any traces of the threat.

Check whether the attack has affected more than one system or device in the case of WORMS.

Check if the backups, credentials, or database have been compromised.

5 - Recovery

After tests and validations confirming that the threat has been contained, the systems can be
restored to operational status.

Restore backup copies stored after verification.


Restore and ensure that systems and devices return to their normal state.
ensuring availability.

6 - Review

After the security incident is resolved, the incident response team must
ensure that all information that may help in the future is documented.
This includes the maintenance of a comprehensive incident report and the execution of a
post-incident monitoring phase.

Fill out the occurrence record document for future reference.


preparation phase.

Post-incident monitoring, thereby ensuring that the threat has been mitigated and that there is no
no trace of it.

Fill out the report of actions taken to be sent to the client along with
preventive technical recommendations, in order to prevent a future attack.

Final considerations

It is of utmost importance to adopt a well-crafted and suitable plan for response to


incidents, this will help us maintain clarity in the midst of a crisis and will change the way
how we are looking at our clients today, thus bringing reliability to the work of
monitoring focused on security.

You might also like