Enterprise Information Security
Contents
Executive Summary 3
Introduction 3
Glossary of terms 4
Distribution List 4
Risk assessment 5
Business Impact Analysis 6
Resource List 6
Function / Services List and description 6
Functions / Services list and impact 7
Functions / Services list and RTO, WRT, MTD and RPO 7
Incident Response Plan 9
Plan overview: 9
Objectives 9
Scope 9
Incident Response Team 9
Collective responsibility of teams: 10
Threat classification, Incident Response and Escalation 11
Incident Response Phases 12
Identification 12
Assessment 12
Containment 12
Eradication 12
Recovery 13
Post Mortem and Documentation 13
Disaster Recovery Plan 13
Plan Overview 13
Objectives 13
Scope of Disaster Recovery Plan 14
PLANNING ASSUMPTIONS 15
Disaster Recovery Team 15
Contact Information 16
Phases in Disaster Recovery 17
Assessment Phase 17
Assessing Severity of Incident or Event 17
Escalating Severe Incidents 18
Assessing Impact 18
Declaring Disaster 18
Recovery Phase 18
Resume Phase 19
Review Phase 19
Facility Recovery Plan 19
Resource Recovery Plan (Servers, WAN, LAN, Firewall) 20
Service Recovery Plan (Such as Payroll, Invoice Management, Communication management) 21
Plan Maintenance 22
Conclusion 22
References 23
Executive Summary
The report specifies an incident response and disaster recovery plan for Megacorp that would allow them to recover from an unfortunate incident. The Incident response Plan responds would help Megacorp identify threat, mitigate it, contain and control it whereas the Disaster Recovery Plan would allow them to recover from disasters. In this report, business would be recovered to a pre-determined Recovery Point Objective within the Recovery Time Objective. Both of the RTO, RPO are identified by the senior management of the organization during planning phases and form an integral part of it. The overall recovery of the disaster would still be within the specified Maximum Tolerable Downtime.
Introduction
Security incidents are on the rise and each passing day more and more zero day exploits are being reported, Megacorp like any other enterprise would need to have an effective plan that allows them to deal with day-to-day security incidents.. A major security breach ends up being a disaster for Megacorp damaging goodwill, brand value and causing financial losses. This is not to say that traditional physical disasters such as fires, floods or thefts are any uncommon. While, Megacorp would need to have an essential and functioning security tha protects them from such incidents, this report deals with what happens when one of such incidents does end up affecting it. The report detailed below lays down an effective plan that would enable Megacorp to be ready to deal with such incidents and to recover from them, if at all, it causes a major disaster. The plan begins by specifying the risks and its corresponding severity as well as the impact the business would have if various resources and services were bound to fail. The disaster recovery plan and incident response plan detailed below would help Megacorp in recovering from multiple unfortunate incidents that relates to disruption of business services.
Glossary of terms
· Backup - An alternative source of data in case primary resource is not working.
· Business continuity planning - It pertains to both incident response as well as disaster recovery planning
· Business Impact analysis - Process of analysis of all business operations and effects a disaster can have on them
· Disaster - Any event which can interrupt in providing services to customers.
· Disaster recovery - Ability to respond to an interruption and bring everything into running.
· Disaster Recovery Plan - The document containing a plan which defines tasks and actions which are required to manage the recovery process.
· Local Area Network - All the systems i.e. computing equipment are located in close proximity with each other.
· Wide Area Network - All the systems i.e. computing equipment are geographically dispersed.
· Recovery Time Objective – The time it takes to recover the systems or services to a last known good working state.
· Recovery Point Objective – The last known good backup state in which to recover the systems or services.
· Work Recovery Time – The additional time taken after the system or service is restored to get it working.
· Maximum Tolerable Downtime – A sum of both RTO and WRT.
Distribution List
Employee ID
Name
Job Profile
Email
E0001
Mr. Rahul Jain
Director
[email protected] E0005
Mr. William John
CEO
[email protected] E0010
Mr. Michael S.
Project Manager
[email protected] E0012
Mr. Rishav K.
IT Manager
[email protected] E0020
Mr. Rajveer Singh
Network Administrator
[email protected]Risk assessment
Resource name
Vulnerability
Probability
Impact
Web Server
High
Medium
High
Sharepoint Server
Medium
Low
Medium
Database Server
Medium
High
High
Exchange Server
Medium
High
High
File Server
Medium
High
High
General Purpose Server
Medium
High
High
WAN and LAN Components
Low
Medium
Low
Firewall and IDS
Medium
Low
High
Email
Low
Medium
Low
Payroll
Medium
Low
Medium
Invoice Management
Low
High
Medium
Communication Management
Medium
Low
Medium
Document Management
Low
Medium
Low
Corporate Intranet Services
Medium
Low
Low
Business Impact Analysis
Resource List
Resource
Description
Web Server
Hosting of company’s website
SharePoint Server
Intranet SharePoint website
Database Server
Hosting of website’s database and internal database
Exchange Server
Hosting of Microsoft Exchange server for emails
File Server
File hosting server
General Purpose Server
General purpose server for IT admin to control other systems, manage deployments and for security
WAN and LAN Components
LAN and WAN Access for the company
Firewall and IDS
Software and hardware based security for protection
Function / Services List and description
Service / Function
Description
Email
Enterprise emailing service based on MS Exchange
Payroll
Payroll and employee attendance system
Invoice Management
Invoice management system for the business
Communication Management
Provides enterprise chat and VOIP services
Document Management
Helps manage company’s document
Corporate Intranet Services
Helps host corporate intranet website using Sharepoint server
Functions / Services list and impact
Service / Function
Impact (Low, Medium and High)
Email
High
Payroll
Low
Invoice Management
High
Communication Management
Medium
Document Management
High
Corporate Intranet Services
Medium
Functions / Services list and RTO, WRT, MTD and RPO in Hours
Service / Function/ Resource
RPO
RTO
WRT
MTD
Web Server
06
12
12
24
SharePoint Server
12
12
06
18
Database Server
12
24
12
36
Exchange Server
01
24
12
36
File Server
24
24
24
48
General Purpose Server
24
12
24
36
WAN and LAN Components
12
12
12
24
Firewall and IDS
24
06
12
18
Email
06
03
01
04
Payroll
12
01
01
02
Invoice Management
12
01
01
02
Communication Management
06
12
01
13
Document Management
06
12
06
18
Corporate Intranet Services
12
01
01
02
Incident Response Plan
Plan overview:
The incident response plan is intended to facilitate timely-effective solution of any damages that could be caused by an incident while also providing a follow-up action and investigation plan.
Objectives
· Being aware about the incident that may be happening or is about to happen by employing detection and monitoring techniques
· Assessing the scope and nature of an incident and examining what kind of customer and other information has been affected.
· Notifying the chief executives as soon as possible whenever an incident involving unauthorized access to customer database happens.
· Ensuring containment and control of incident by taking recommended steps.
· Notifying customers if their data is severely affected or if they are required to take...