RS · RESPOND

Reagieren

Bei einem erkannten Cybersicherheitsvorfall werden Maßnahmen ergriffen, um seine Auswirkungen einzudämmen.

4 Kategorien · 13 Ergebnisziele

RS.MA

Vorfallmanagement (Incident Management)

Reaktionen auf erkannte Cybersicherheitsvorfälle werden gesteuert.

RS.MA-01

Der Vorfallreaktionsplan wird nach Deklaration eines Vorfalls in Abstimmung mit relevanten Dritten ausgeführt.

Drittrisiko

NIST-Originalwortlaut: The incident response plan is executed in coordination with relevant third parties once an incident is declared

Umsetzungsbeispiele (4)
  • Detection technologies automatically report confirmed incidents
  • Request incident response assistance from the organization's incident response outsourcer
  • Designate an incident lead for each incident
  • Initiate execution of additional cybersecurity plans as needed to support incident response (for example, business continuity and disaster recovery)
RS.MA-02

Vorfallmeldungen werden triagiert und validiert.

Eigenrisiko

NIST-Originalwortlaut: Incident reports are triaged and validated

Umsetzungsbeispiele (2)
  • Preliminarily review incident reports to confirm that they are cybersecurity-related and necessitate incident response activities
  • Apply criteria to estimate the severity of an incident
RS.MA-03

Vorfälle werden kategorisiert und priorisiert.

Eigenrisiko

NIST-Originalwortlaut: Incidents are categorized and prioritized

Umsetzungsbeispiele (3)
  • Further review and categorize incidents based on the type of incident (e.g., data breach, ransomware, DDoS, account compromise)
  • Prioritize incidents based on their scope, likely impact, and time-critical nature
  • Select incident response strategies for active incidents by balancing the need to quickly recover from an incident with the need to observe the attacker or conduct a more thorough investigation
RS.MA-04

Vorfälle werden bei Bedarf eskaliert.

Eigenrisiko

NIST-Originalwortlaut: Incidents are escalated or elevated as needed

Umsetzungsbeispiele (2)
  • Track and validate the status of all ongoing incidents
  • Coordinate incident escalation or elevation with designated internal and external stakeholders
RS.MA-05

Die Kriterien zur Einleitung der Wiederherstellung werden angewendet.

Eigenrisiko

NIST-Originalwortlaut: The criteria for initiating incident recovery are applied

Umsetzungsbeispiele (2)
  • Apply incident recovery criteria to known and assumed characteristics of the incident to determine whether incident recovery processes should be initiated
  • Take the possible operational disruption of incident recovery activities into account
RS.AN

Vorfallanalyse (Incident Analysis)

Untersuchungen werden durchgeführt, um eine wirksame Reaktion sicherzustellen und Forensik sowie Wiederherstellung zu unterstützen.

RS.AN-03

Es wird analysiert, was während eines Vorfalls geschehen ist, und die Grundursache wird ermittelt.

Eigenrisiko

NIST-Originalwortlaut: Analysis is performed to establish what has taken place during an incident and the root cause of the incident

Umsetzungsbeispiele (4)
  • Determine the sequence of events that occurred during the incident and which assets and resources were involved in each event
  • Attempt to determine what vulnerabilities, threats, and threat actors were directly or indirectly involved in the incident
  • Analyze the incident to find the underlying, systemic root causes
  • Check any cyber deception technology for additional information on attacker behavior
RS.AN-06

Während einer Untersuchung durchgeführte Aktionen werden aufgezeichnet; Integrität und Herkunft der Aufzeichnungen werden bewahrt.

Eigenrisiko

NIST-Originalwortlaut: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved

Umsetzungsbeispiele (2)
  • Require each incident responder and others (e.g., system administrators, cybersecurity engineers) who perform incident response tasks to record their actions and make the record immutable
  • Require the incident lead to document the incident in detail and be responsible for preserving the integrity of the documentation and the sources of all information being reported
RS.AN-07

Vorfalldaten und -metadaten werden gesammelt; ihre Integrität und Herkunft werden bewahrt.

Eigenrisiko

NIST-Originalwortlaut: Incident data and metadata are collected, and their integrity and provenance are preserved

Umsetzungsbeispiele (1)
  • Collect, preserve, and safeguard the integrity of all pertinent incident data and metadata (e.g., data source, date/time of collection) based on evidence preservation and chain-of-custody procedures
RS.AN-08

Das Ausmaß eines Vorfalls wird geschätzt und validiert.

Eigenrisiko

NIST-Originalwortlaut: An incident's magnitude is estimated and validated

Umsetzungsbeispiele (2)
  • Review other potential targets of the incident to search for indicators of compromise and evidence of persistence
  • Automatically run tools on targets to look for indicators of compromise and evidence of persistence
RS.CO

Berichterstattung und Kommunikation zur Vorfallreaktion (Incident Response Reporting and Communication)

Reaktionsaktivitäten werden mit internen und externen Stakeholdern abgestimmt, wie es Gesetze, Vorschriften oder Richtlinien erfordern.

RS.CO-02

Interne und externe Stakeholder werden über Vorfälle benachrichtigt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Internal and external stakeholders are notified of incidents

Umsetzungsbeispiele (3)
  • Follow the organization's breach notification procedures after discovering a data breach incident, including notifying affected customers
  • Notify business partners and customers of incidents in accordance with contractual requirements
  • Notify law enforcement agencies and regulatory bodies of incidents based on criteria in the incident response plan and management approval
RS.CO-03

Informationen werden mit benannten internen und externen Stakeholdern geteilt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Information is shared with designated internal and external stakeholders

Umsetzungsbeispiele (6)
  • Securely share information consistent with response plans and information sharing agreements
  • Voluntarily share information about an attacker's observed TTPs, with all sensitive data removed, with an Information Sharing and Analysis Center (ISAC)
  • Notify HR when malicious insider activity occurs
  • Regularly update senior leadership on the status of major incidents
  • Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
  • Coordinate crisis communication methods between the organization and its critical suppliers
RS.MI

Schadensbegrenzung bei Vorfällen (Incident Mitigation)

Es werden Maßnahmen ergriffen, um die Ausbreitung eines Ereignisses zu verhindern und seine Auswirkungen zu mindern.

RS.MI-01

Vorfälle werden eingedämmt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Incidents are contained

Umsetzungsbeispiele (4)
  • Cybersecurity technologies (e.g., antivirus software) and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform containment actions
  • Allow incident responders to manually select and perform containment actions
  • Allow a third party (e.g., internet service provider, managed security service provider) to perform containment actions on behalf of the organization
  • Automatically transfer compromised endpoints to a remediation virtual local area network (VLAN)
RS.MI-02

Vorfälle werden beseitigt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Incidents are eradicated

Umsetzungsbeispiele (3)
  • Cybersecurity technologies and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform eradication actions
  • Allow incident responders to manually select and perform eradication actions
  • Allow a third party (e.g., managed security service provider) to perform eradication actions on behalf of the organization