An Exemplar Incident Response Plan for Security Operations Centre Analysts
摘要
The significance of a cyber security incident response plan cannot be overemphasised, especially at a time when cyberattacks are becoming increasingly prevalent and sophisticated. Organisations need to have a focused and coordinated approach when responding to cyber incidents. Security Operations Centres (SOCs) need a well-defined incident response plan to facilitate detection and response activities in the event of a cyberattack. While there are several well-known incident response plans, these plans typically have a broad scope and are designed to assist teams and organisations to develop their own incident handling processes. Previous studies propose a tailored incident response plan for the Computer Security Incident Response Team (CSIRT). This paper presents an example incident response plan for SOC analysts. The proposed approach leverages the United States National Institute of Standards and Technology (NIST) incident response framework. The proposed approach will be beneficial to analysts with varying levels of experience/expertise, especially junior and early-career analysts, since research indicates that these categories of analysts are burdened by the complexity of security incident analysis.