Objective: Recommended Control 3: To identify and implement processes for incident analysis and selection of appropriate remedies which will assist in preventing future information security incidents report the information security incident and perform any other activities specified in the IRP in the worst case scenario, rebuild and reinitialize the system For evidence gathering, agencies should: transfer a copy of raw audit trails and other relevant data onto media for secure archiving, as well as securing manual log records for retention ensure that all personnel involved in the investigation maintain a record of actions undertaken to support the investigation Ensuring that system users are aware of reporting procedures will assist in identifying any information security incidents that an ITSM, or system owner fail to notice. The purpose of recording information security incidents within a register is to highlight the nature and frequency of information security incidents so that corrective action can be taken. This information can subsequently be used as an input into future security risk assessments of systems. A data spill is defined as the unauthorized or unintentional release, transmission or transfer of data. The guidance for handling malicious code infections is provided to assist in preventing the spread of the infection and to prevent reinfection. Important details include: the infection date of the machine the possibility that system records and logs could be compromised the period of infection A complete operating system reinstallation, or an extensive comparison of checksums or other characterization information, is the only reliable way to ensure that malicious code is eradicated. While gathering evidence it is important to maintain the integrity of the information and the chain of evidence. Even though in most cases an investigation does not directly lead to a police prosecution, it is important that the integrity of evidence such as manual logs, automatic audit trails and intrusion detection tool outputs be protected. 46

Select target paragraph3