Reference no: EM132210036
Assignment 3: Incident Response (IR) Strategic Decisions
Suppose that you have been alerted of a potential incident involving a suspected worm spreading via buffer overflow techniques, compromising Microsoft IIS Web servers. As the IR Team leader, it is your responsibility to determine the next steps.
Write a two to three (2-3) page paper in which you:
1. Explain in detail the initial steps that would need to be made by you and the IR team in order to respond to this potential incident.
2. Construct a process-flow diagram that illustrates the process of determining the incident containment strategy that would be used in this scenario, and identify which containment strategy would be appropriate in this case, through the use of graphical tools in Visio, or an open source alternative such as Dia. Note: The graphically depicted solution is not included in the required page length.
3. Construct a process flow diagram to illustrate the process(es) for determining if / when notification of the incident should be relayed to upper management, and explain how those communications should be structured and relayed through the use of graphical tools in Visio, or an open source alternative such as Dia. Note: The graphically depicted solution is not included in the required page length.
4. Detail the incident recovery processes for the resolution of this incident.
5. Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources.
Your assignment must follow these formatting requirements:
• Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow APA or school-specific format. Check with your professor for any additional instructions.
• Include a cover page containing the title of the assignment, the student's name, the professor's name, the course title, and the date. The cover page and the reference page are not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:
• Summarize the various types of disasters, response and recovery methods.
• Develop techniques for different disaster scenarios.
• Use technology and information resources to research issues in disaster recovery.
• Write clearly and concisely about disaster recovery topics using proper writing mechanics and technical style conventions.
How cloud-based services change incident response
: Discuss from your perspective how cloud-based services change incident response, for better or worse, and determine what you believe to be the greatest.
|
Create a hypothetical organization with details
: Create a hypothetical organization with details including geographic location(s), number of employees in each location, primary business functions.
|
Describe the proper procedures and policies
: Describe the proper procedures and policies that would be implemented specific to the DR team personnel as well as special equipment that would be required.
|
Explain how the attacks affected risk management
: Explain how the attacks affected risk management in organizations and have prompted an increased justification for recovery-based objectives, initiatives.
|
Construct a process-flow diagram using given information
: Construct a process-flow diagram that illustrates the process of determining the incident containment strategy that would be used in this scenario.
|
Discuss in detail the role that an ids-ips would play
: Discuss in detail the role that an IDS / IPS would play in the IR efforts, and explain how these systems can assist in the event notification, determination.
|
Summarize various types of disasters and recovery methods
: Read the article titled "When Stuxnet Hit the Homeland: Government Response to the Rescue," from ABC News and consider this threat in terms of incident response
|
Explain the basic primary tasksand major policy
: Explain the basic primary tasks, ongoing evaluations, and major policy and procedural changes that would be needed to perform as the BC lead / manager.
|
Guess an integer that the user has picked
: Write a program that will guess an integer that the user has picked. Imagine that the user will write down a positive integer x on a piece of paper.
|