<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incident Response Policy and Procedures in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24139#M64</link>
    <description>&lt;P&gt;NIST, SANS, all have rather comprehensive documentations and templates on IRT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check out ITIL- Service Operation, on incident management, a fairly concise guideline on incident and response process, including a good&amp;nbsp; diagram on the flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2019 20:55:06 GMT</pubDate>
    <dc:creator>Chuxing</dc:creator>
    <dc:date>2019-06-24T20:55:06Z</dc:date>
    <item>
      <title>Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24136#M63</link>
      <description>&lt;P&gt;Any recommendations for a Incident Response Policy and Procedures template?&lt;/P&gt;&lt;P&gt;I'm building a cyber program from scratch.&lt;/P&gt;&lt;P&gt;Any guidance is appreciated.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Linda&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:14:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24136#M63</guid>
      <dc:creator>Lwhite</dc:creator>
      <dc:date>2023-10-09T09:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24139#M64</link>
      <description>&lt;P&gt;NIST, SANS, all have rather comprehensive documentations and templates on IRT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check out ITIL- Service Operation, on incident management, a fairly concise guideline on incident and response process, including a good&amp;nbsp; diagram on the flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 20:55:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24139#M64</guid>
      <dc:creator>Chuxing</dc:creator>
      <dc:date>2019-06-24T20:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24147#M65</link>
      <description>&lt;P&gt;My organization bases our policy and procedures on NIST 800 framework. The NIST 800-61 Computer security Incident guide is extremely helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 00:52:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24147#M65</guid>
      <dc:creator>twoand4</dc:creator>
      <dc:date>2019-06-25T00:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24148#M66</link>
      <description>&amp;gt; Lwhite (Newcomer II) posted a new topic in Welcome on 06-24-2019 04:06 PM in the&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Any recommendations for a Incident Response Policy and Procedures template?&lt;BR /&gt;&lt;BR /&gt;Ha!&lt;BR /&gt;&lt;BR /&gt;I guess my reaction is a little different than most: having started out in malware&lt;BR /&gt;research (way back when it was possible) good IR was about the first to work on.&lt;BR /&gt;&lt;BR /&gt;More recently I've been doing a 2-4 hour IRP presentation with a one-page&lt;BR /&gt;handout as an inducement to quick and dirty "get started, durnit!" activity ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;This is primarily an investigative unit and I don't think we&lt;BR /&gt;should get sidetracked into the finer details of technology.&lt;BR /&gt;- Chief Superintendent Len Hynds&lt;BR /&gt;head of the UK National Hi-Tech Crime Unit&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Tue, 25 Jun 2019 01:00:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24148#M66</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-06-25T01:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24152#M67</link>
      <description>&lt;P&gt;As stated by others, the NIST Special Publication 800-61 Revision 2 is a good starting point. You can find it here:&amp;nbsp;&lt;A href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf" target="_blank"&gt;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have any workloads in the cloud you will need to adapt to account for any shared responsibilities/CSP requirements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 02:40:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24152#M67</guid>
      <dc:creator>ScottNicholson</dc:creator>
      <dc:date>2019-06-25T02:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24155#M68</link>
      <description>&lt;P&gt;An alternative you could look at is ISO 27035, as a top level approach.&amp;nbsp; It'll also make sense to outline a playbook for each general type of incident.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You'll need to determine if you can have a permanent CSIRT or if you'll need to pull together a virtual CSIRT at the point of detecting major incident.&amp;nbsp; This will probably depend on your organisations business and its resource budget.&amp;nbsp; vCSIRT can work, but can also be problematic as getting the time to train and rehearse when there is actually an incident can be a tough ask with the members line management.&amp;nbsp; A common solution is to have first call on staff from your SoC or pay a retainer to a third party for first responders.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 07:24:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24155#M68</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-06-25T07:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24396#M69</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 01:56:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/24396#M69</guid>
      <dc:creator>Lwhite</dc:creator>
      <dc:date>2019-06-28T01:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Response Policy and Procedures</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/26299#M70</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;I found that this thread did not have any answer and therefore would like to put my thoughts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIST's Cyber Security Maturity Assessment Framework can be a good start as it has a dedicated domain on Incident Management life cycle.&amp;nbsp; In addition, inputs from well known security standards such as ISO 27001 and PCI DSS (current version 4.0) should also be considered.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy which is a high level document must be specific to the organization, the business units, operating environment and in line with the risk appetite of the organization.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Aug 2019 14:22:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Incident-Response-Policy-and-Procedures/m-p/26299#M70</guid>
      <dc:creator>Shwetaksagar</dc:creator>
      <dc:date>2019-08-03T14:22:55Z</dc:date>
    </item>
  </channel>
</rss>

