Assignment 3: Incident Response (IR) Strategic Decisions
Suppose that you have been alerted of a potential incident involving a suspected worm spreading via buffer overflow techniques, compromising Microsoft IIS Web servers. As the IR Team leader, it is your responsibility to determine the next steps.
Write a two to three (2-3) page paper in which you:
- Explain in detail the initial steps that would need to be made by you and the IR team in order to respond to this potential incident.
- Construct a process-flow diagram that illustrates the process of determining the incident containment strategy that would be used in this scenario, and identify which containment strategy would be appropriate in this case, through the use of graphical tools in Visio, or an open source alternative such as Dia. Note: The graphically depicted solution is not included in the required page length.
- Construct a process flow diagram to illustrate the process(es) for determining if / when notification of the incident should be relayed to upper management, and explain how those communications should be structured and relayed through the use of graphical tools in Visio, or an open source alternative such as Dia. Note: The graphically depicted solution is not included in the required page length.
- Detail the incident recovery processes for the resolution of this incident.
- Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources.
Your assignment must follow these formatting requirements:
- This course requires use of new Strayer Writing Standards (SWS). The format is different than other Strayer University courses. Please take a moment to review the SWS documentation for details.
- Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow SWS or school-specific format. Check with your professor for any additional instructions.
- Include a cover page containing the title of the assignment, the student’s name, the professor’s name, the course title, and the date. The cover page and the reference page are not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:
- Summarize the various types of disasters, response and recovery methods.
- Develop techniques for different disaster scenarios.
- Use technology and information resources to research issues in disaster recovery.
- Write clearly and concisely about disaster recovery topics using proper writing mechanics and technical style conventions.
Explanation & Answer
kindly find the attached completed work. Thank You.
Running head: INCIDENT RESPONSE (IR) STRATEGIC DECISIONS
Incident Response (IR) Strategic Decisions
Institution of Affiliation
INCIDENT RESPONSE (IR) STRATEGIC DECISIONS
For this case scenario, the following steps would be followed as the initial steps in incident
a) Preparation: this step will entail taking all preliminary measures to prepare to respond to
the incident adequately. Such measures and actions will include developing and
documenting incident response policies, defining the communication guidelines,
assessing the threat detection capability, and incorporating threat intelligence feeds
b) Detection and reporting: This will entail active monitoring of the security events with the
aim of detecting, alerting, and reporting on the incidence. Here, security events will be
monitored using firewalls, data loss prevention, and intrusion prevention systems.
Alerting will involve creating an incident...