Propose an incident response plan to prepare an organization in the event of an attack.

. Question
Each unit in this module explores one of the three crucial areas of cybersecurity management that need to be considered when developing an incident response plan. This ongoing project requires you to use the knowledge gained from each of the three units to formulate and complete the 10 steps of an incident response plan, as identified in the notes from Unit 1.

If you are completing your ongoing project on Sony, you are required to create an incident response plan that the organization should have followed in light of the 2014 hack. For example, detail the detection, analysis, and containment strategies it should have employed, the crisis communications plan it should have adhered to, and recommendations for successful eradication and recovery.

Note:

All ongoing project submissions throughout the course need to focus on the same organization. Or, if you choose to focus on the case study of Sony, you will need to complete all your submissions on Sony.

It is highly recommended that you avoid disclosing any confidential information in your assignments. Although you are encouraged to draw on real-world experience during the course, you are urged to use pseudonyms (false names) and alter any sensitive details or data where necessary. You are responsible for ensuring that you do not disclose any information that is protected by confidentiality undertakings; all information is treated in accordance with our privacy policy.

Please read Section 4 of the Honor Code in the Orientation Module course handbook for more guidance.

This assignment requires you to complete the 10 steps of an incident response plan. Use the suggested word counts for each section as a guide for how much detail should be contained under each step.

Introduction
It is important for your incident response strategy to meet the requirements of your organizational context. Write a short introduction summarizing your type of organization, and an overview of the business-critical assets your organization relies on. You can use the information you provided in Module 3’s ongoing project, or Module 5’s online activity submission.

(Approx. 150 words)

Start writing here:

Step 1: Prevention
Describe the measures your organization will take to protect against a cyberattack from both a technical and non-technical perspective.

(Approx. 150 words)

Start writing here:

Step 2: Planning
List the individuals involved in your incident response team and their roles. Ensure that the roles, responsibilities, and structure of your team meets the requirements of your organizational context.

A cyber crisis communication plan is compiled in this phase, but in this incident response plan, include your plan under Step 7: Communication.

(Approx. 200 words)

Start writing here:

Step 3: Preparation
Section 2.3 in Unit 1’s notes details a number of requirements in this step, including reporting mechanisms, the preparation of checklists and jump bags, and auditing procedures. However, for the purpose of this ongoing project, you are required to detail one training exercise the incident response team will undergo. Include specific examples of scenarios or questions, and explain why you have chosen it.

(Approx. 150 words)

Start writing here:

Step 4: Detection
List the tools your organization would use to detect a breach.

(Approx. 150 words)

Start writing here:

Step 5: Analysis
Explain how your organization would analyze whether an incident is a cyberattack. Also describe how you would categorize and prioritize cyberattacks in your organization.

(Approx. 200 words)

Start writing here:

Step 6: Containment
Describe how your organization would prevent a cyberattack from spreading further.

(Approx. 200 words)

Start writing here:

Step 7: Communication
As per Section 4 of the Unit 2 notes, compile a cyber crisis communication plan detailing the internal and external stakeholders your organization would need to communicate to in the event of a breach. Describe what communication channels would be used to communicate with these stakeholders.

(Approx. 250 words)

Start writing here:

Step 8: Eradication
Provide insight into the approaches and decisions the team will take to remove the threat from your organization’s internal system.

(Approx. 150 words)

Start writing here:

Step 9: Recovery
Describe what steps your organization will take to return to its normal operations.

(Approx. 150 words)

Start writing here:

Step 10: Post-event analysis
List the processes that would need to be followed to ensure that lessons learned are implemented.

(Approx. 150 words)

Start writing here:

Note:

The incident response plan is a central part of an organization’s cyber risk mitigation strategy. However, as you will not have an opportunity to revise your plan based on your Tutor’s feedback in time for Module 8, you will not be required to integrate it into your final risk mitigation strategy. Please consult the grading breakdown in the Orientation Module course handbook for more information.

× How can I help you?