NIST CSF · Domain 4
Respond
About 20% of the exam
Respond categories in 2.0
- RS.MA
- incident management
- RS.AN
- incident analysis
- RS.CO
- response reporting and communication
- RS.MI
- incident mitigation
- Moved out
- improvements now live in ID.IM
- Trigger
- an incident has been declared
- Handover
- recovery begins once containment holds
Lessons learned no longer sit inside Respond; CSF 2.0 moved improvement outcomes into the Identify function
The response sequence
- Declare
- Execute the plan
- Triage and categorize
- Analyze scope
- Contain
- Eradicate
- Notify stakeholders
- Hand to recovery
- Declaration
- starts the plan and the clock
- Categorization
- severity decides who gets involved
- Containment
- stop the spread first
- Eradication
- remove the attacker foothold
- Evidence
- preserved before systems are rebuilt
- Closure
- only once recovery completes
Incident analysis
- Establish scope before acting broadly
- Preserve volatile memory before shutdown
- Timeline built from correlated logs
- Root cause separated from symptoms
- Chain of custody maintained throughout
- Analysis drives the containment choice
Containment options
- Network isolation
- cut the host or segment
- Account disablement
- stop the credential being used
- DNS sinkhole
- redirect malicious domain lookups
- Perimeter block
- break command and control
- Rebuild
- when the host cannot be trusted
- Trade off
- evidence loss versus faster containment
Communication duties
- Notification matrix decided in advance
- Management updated on a set cadence
- Regulators notified within legal deadlines
- Customers told what actually affects them
- Law enforcement engaged where appropriate
- One spokesperson, one message
- Everything said gets logged
Hard response scenarios
- Insider threat
- they know the tools and procedures
- Long dwell time
- logs may not reach back far
- Encrypted traffic
- behavior analysis over payload inspection
- Supplier compromise
- your plan depends on theirs
- Overlapping deadlines
- different regulators, different clocks
- Ransomware
- containment and recovery run together
When the attacker already knows your playbook, change the playbook before you run it
Response readiness
- Plan written, approved and current
- Roles named with deputies
- Contact list tested, not assumed
- Retainer with an external responder
- Tabletop exercises at least annually
- Out of band communications ready
Evidence handling
- Capture memory before disk imaging
- Hash images at collection time
- Record who touched what and when
- Store originals, work on duplicates
- Legal hold suspends normal deletion
Metrics that matter
- Time to detect
- how long before anyone noticed
- Time to contain
- declaration to containment achieved
- Time to remediate
- containment to eradication complete
- Business impact
- downtime, cost and records affected
- Repeat rate
- incidents from the same cause
After the incident
- Review held soon after recovery
- Timeline and decisions examined honestly
- Improvements routed into ID.IM
- Plan updated with what failed
- Detections added for what was missed
Rapid recall: who to tell
- Executive team
- severity and business impact
- Legal
- obligations and legal privilege
- Regulator
- within the statutory deadline
- Customers
- what affects them, plainly stated
- Insurer
- as the policy requires
- Law enforcement
- where a crime is suspected
Respond versus Recover
- Respond stops the bleeding
- Recover restores the service
- Containment and eradication sit in Respond
- Restoration and validation sit in Recover
- Communication runs through both
Reference strip: declare, analyze, contain, communicate, close
Declare
- Threshold met, plan executed
- Severity set, roles activated
- Clock starts for notifications
Analyze
- Scope before broad action
- Volatile evidence captured first
- Timeline from correlated logs
Contain
- Isolate, disable, block, rebuild
- Weigh evidence against speed
- Eradicate the foothold after
Communicate
- Matrix agreed in advance
- Regulators on statutory clocks
- One voice to the outside
Close
- Only once recovery finishes
- Review while memory is fresh
- Improvements routed to ID.IM
Quick exam traps
- Trap: Lessons learned is a Respond outcome in CSF 2.0
- Trap: Containment should wait until the root cause is fully known
- Trap: Shutting the machine down is the safest first move
- Trap: One regulatory deadline covers every jurisdiction involved
- Trap: The incident closes when the attacker is removed
- Trap: Rebuilding a host is always preferable to isolating it
cybercertprep.com · original revision sheet written from the public body of knowledge