Reference no: EM131257941
Assignment: Incident Response (IR) Revamp
Imagine you have just taken over the manager position for your organization's incident response team, after coming from another division in the company. Your first realization is that proper procedures, best practices, and sound technologies are not being utilized. You decide to revamp the team's efforts.
Write a two to three (3-4) page paper in which you:
1. Explicate the main efforts that would be included in the incident response efforts, including but not limited to personnel and team structure, tools and utilities, and proper procedures.
2. Discuss in detail the role that an IDS / IPS would play in the IR efforts, and explain how these systems can assist in the event notification, determination, and escalation processes.
3. Explain how the NIST SP800-61, Rev. 1 could assist the personnel in classifying incidents so each is identified appropriately and the proper incident-handling procedures are taken.
4. Explain how the use of log management systems (e.g., Splunk) could be a legitimate and useful component of the IR efforts, and describe the potential issues that could arise if not utilized.
5.Use at least three (3) quality resources in this assignment.
Determine the company resources and capabilities
: Determine the company's resources, capabilities, and core competencies. Analyze the company's value chain to determine where they can create value using the resources, capabilities, and core competencies discussed above
|
What are the limitations of the learning curve in given case
: What are the advantages and disadvantages to IBM and SMT from this approach? - How does SMT's proposed learning rate compare with that of other industries?
|
Evaluate the use of internal vs. external motivators
: For your response post, choose another student's summary and share your thoughts about how an OD intervention could be implemented to make the change easier on employees. Evaluate the use of internal vs. external motivators.
|
What is true about the formation of a sole proprietorship
: What is true about specific performance as an equitable remedy for contract breaches? What is true about the formation of a sole proprietorship? Identify the true statement about general partnerships.
|
Discuss in detail the role that an ids would play
: Discuss in detail the role that an IDS / IPS would play in the IR efforts, and explain how these systems can assist in the event notification, determination, and escalation processes
|
Compare the sales of two products
: Explain how graphs can be used to compare the sales of two products. Include an estimate of the year in which the CD units sold equaled the music videos sold.
|
Discuss the efforts of ics-cert specifically to the stuxnet
: Discuss the efforts of ICS-CERT specifically to the Stuxnet threat and examine its incident response efforts to mitigate this risk against U.S. industrial systems
|
Reasonable measure of tara distance
: Twelve hours ago, Tara had traveled 62 miles from her starting point in California.Which is a reasonable measure of Tara's distance from her starting point in California now?
|
Determine if the change you are suggesting is a process
: For this module's project component, develop an annotated bibliography using at least 4 sources that will help you write your plan. Follow the steps below to determine the most beneficial mix of resources.
|