《网络安全事件和漏洞响应手册》-43页_1mb
报告摘要
Cybersecurity Incident & Vulnerability Response Playbooks Summary
Core Content
The Cybersecurity and Infrastructure Security Agency (CISA) has developed two standardized playbooks for FCEB (Federal Civilian Executive Branch) agencies to respond to cybersecurity incidents and vulnerabilities. These playbooks provide a framework for identifying, coordinating, remediating, recovering, and tracking mitigations from cyber threats that affect FCEB systems, data, and networks. The goal is to enhance the federal government's cybersecurity response by standardizing shared practices, improving coordination, and ensuring consistent and effective actions.
Main Objectives
- Standardize incident and vulnerability response procedures across FCEB agencies.
- Improve coordination and communication between agencies and CISA.
- Enhance preparedness by defining baseline systems, establishing response plans, and ensuring technical infrastructure is in place.
- Facilitate detection and analysis of cyber threats using threat intelligence and technical analysis tools.
- Enable containment, eradication, and recovery of systems and data affected by incidents.
- Support post-incident activities to document, review, and improve future response efforts.
Key Information
Scope
- The playbooks apply to FCEB entities and cover response activities initiated by:
- FCEB agencies themselves
- CISA or third parties (e.g., law enforcement, intelligence agencies, commercial organizations, contractors, and service providers)
- They do not cover classified information or National Security Systems (NSS) incidents. For those, agencies should refer to CNSSI1010.
Audience
- Applies to all FCEB agencies, their information systems, contractors, and third-party ICT service providers.
- ICT service providers contracted by FCEB agencies are required to promptly report incidents to the agencies and CISA.
When to Use the Playbooks
- Incident Response Playbook is used for incidents involving confirmed malicious activity where a major incident has been declared or is suspected.
- Vulnerability Response Playbook applies to actively exploited vulnerabilities.
Incident Response Process
The process is divided into five phases:
- Preparation
- Detection & Analysis
- Containment
- Eradication & Recovery
- Post-Incident Activities
Each phase includes specific activities, tools, and procedures to ensure a structured and effective response.
Preparation Phase
- Policies and Procedures: Develop and document incident response plans, including roles and escalation processes.
- Instrumentation: Implement telemetry and monitoring tools such as AV, EDR, DLP, IDPS, SIEM, and CDM.
- Trained Personnel: Ensure staff is trained and ready for response, including COOP and failover/recovery testing.
- Cyber Threat Intelligence (CTI): Monitor and integrate threat intelligence feeds, including atomic, computed, and behavioral indicators.
- Active Defense: Use techniques like honeytokens, sandboxing, and dark nets to delay adversary discovery and study their behavior.
- Communications and Logistics: Define communication protocols and out-of-band coordination mechanisms.
- Operational Security (OPSEC): Protect IR activities from detection by adversaries.
- Technical Infrastructure: Implement tools for forensic analysis, data collection, and evidence preservation.
Detection & Analysis
- Declare Incident: Report to CISA and alert IT leadership.
- Investigation Scope: Use data to determine access type, asset impact, and adversary tactics.
- Collect and Preserve Data: Gather logs and evidence from perimeter, internal network, and endpoints.
- Technical Analysis: Correlate data to identify root causes and adversary TTPs.
- Correlate Events and Document Timeline: Use logs and event data to track the timeline of the incident.
- Identify Anomalous Activity: Detect subtle signs of adversary behavior, including use of legitimate tools.
- Analyze for Common TTPs: Compare to the MITRE ATT&CK framework to understand adversary intent and methods.
- Validate and Refine Scope: Update the investigation scope as new information is gathered.
Containment
- Objective: Prevent further damage and reduce the impact of the incident.
- Strategies: Vary based on the type of incident (e.g., fileless malware vs. ransomware).
- Considerations:
- Impact on mission operations and services.
- Duration and resource requirements.
- Evidence collection and preservation.
- Third-Party Support: CISA may provide threat hunting teams or collaborate with NSA or U.S. Cyber Command for assistance.
Vulnerability Response Playbook
- Focuses on vulnerabilities being actively exploited.
- Includes preparation, identification, evaluation, remediation, and reporting phases.
- Encourages continuous sharing of threat intelligence with CISA via Automated Indicator Sharing (AIS) and Cyber Threat Indicator and Defensive Measures Submission System.
Appendices
- Appendix A: Key cybersecurity terms and definitions.
- Appendix B: Incident Response Checklist.
- Appendix C: Incident Response Preparation Checklist.
- Appendix E: Vulnerability and Incident Categories.
- Appendix F: Source text and references.
- Appendix G: Whole-of-Government roles and responsibilities.
Conclusion
These playbooks are designed to improve coordinated and effective cybersecurity response across the federal government. They incorporate industry best practices and lessons learned from past incidents, while promoting standardization, information sharing, and resilience in the face of cyber threats. Future iterations may be adapted for use by non-FCEB organizations.
试读结束,高清完整版pdf/doc/ppt,请点下载