The Response Function describes activities that will help an agency to take action regarding a detected cybersecurity event. These activities will support the ability to contain the impact of a potential cybersecurity event.
Response Planning
Executing and maintaining response processes to ensure timely response to detected cybersecurity events.
- Execute the response plan during or after a cybersecurity event.
Associated Artifacts:
Communications
Coordinating response activities with internal and external stakeholders, as appropriate, to include external support from law enforcement agencies.
- Ensure personnel know their roles and order of operations (i.e. ensure personnel know which actions or tasks to complete in the correct order and within any required timeframes) when a response is needed.
- Report all cybersecurity events according to established criteria.
- Ensure information is shared according to documented response plans.
- Ensure coordination with stakeholders occurs according to documented response plans.
- Ensure voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness (i.e. maintaining knowledge and an understanding of the security health and operations of the network, the possible cybersecurity threats, and business/mission dependencies) .
Analysis
Conducting analysis to ensure adequate response and support recovery activities.
- Investigate all notifications from detection systems.
- Ensure the impact of all incidents are understood.
- Perform forensics to understand why and how systems are attacked, and to understand how to prevent future attacks.
- Categorize all incidents according to response plans.
- Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g. internal testing, security bulletins, or security researchers) .
Mitigation
Performing activities to prevent expansion of an event, mitigate its effects, and eradicate the incident.
- Contain incidents to prevent expansion to other systems or other areas of the network.
- Mitigate incidents to reduce the effect of the event.
- Mitigate newly identified vulnerabilities or document them as accepted risks.
Improvements
Improving agency response activities by incorporating lessons learned from current and previous detection/response activities.
- Incorporate lessons learned into response plans.
- Periodically update response strategies.