Objective:
Recommended Control 3:
To identify and implement processes for incident analysis and
selection of appropriate remedies which will assist in preventing
future information security incidents
report the information security incident and perform any
other activities specified in the IRP
in the worst case scenario, rebuild and reinitialize the
system
For evidence gathering, agencies should:
transfer a copy of raw audit trails and other relevant data
onto media for secure archiving, as well as securing manual
log records for retention
ensure that all personnel involved in the investigation
maintain a record of actions undertaken to support the
investigation
Ensuring that system users are aware of reporting procedures will assist in identifying any
information security incidents that an ITSM, or system owner fail to notice.
The purpose of recording information security incidents within a register is to highlight the nature
and frequency of information security incidents so that corrective action can be taken. This
information can subsequently be used as an input into future security risk assessments of systems.
A data spill is defined as the unauthorized or unintentional release, transmission or transfer of data.
The guidance for handling malicious code infections is provided to assist in preventing the spread of
the infection and to prevent reinfection. Important details include:
the infection date of the machine
the possibility that system records and logs could be compromised
the period of infection
A complete operating system reinstallation, or an extensive comparison of checksums or other
characterization information, is the only reliable way to ensure that malicious code is eradicated.
While gathering evidence it is important to maintain the integrity of the information and the chain
of evidence. Even though in most cases an investigation does not directly lead to a police
prosecution, it is important that the integrity of evidence such as manual logs, automatic audit trails
and intrusion detection tool outputs be protected.
46