Incedent Response S...
 
Notifications
Clear all

Incedent Response SOP Needed

15 Posts
6 Users
0 Reactions
1,032 Views
(@cirillop)
Active Member
Joined: 19 years ago
Posts: 14
Topic starter  

I am in need of a IR template SOP can anyone help it is for a windows enviroment.


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Can you provide more information? Are you looking for something purely technical, independent of infrastructure? Or are there political and infrastructure issues?

H


   
ReplyQuote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
 

You might want to check out FIRST. http//first.org


   
ReplyQuote
(@condar)
New Member
Joined: 19 years ago
Posts: 1
 

In addition to FIRST, also consider checking out the NIST Special Publications. One in particular that may be of use is NIST SP800-61, "Computer Security Incident Handling Guide," found here
http//csrc.nist.gov/publications/nistpubs/800-61/sp800-61.pdf#search=%22nist%20sp800-61%22

There are several other NIST SPs that may be of use to you, but the numbers escape me at the moment. SP800-61 has great guidelines for a phased approach to incident response, including checklists for various categories of incidents. It's a long document, but at least check out section 3, Handling an Incident, if nothing else.

-James


   
ReplyQuote
psu89
(@psu89)
Estimable Member
Joined: 20 years ago
Posts: 118
 

This may also help.

http//ncfs.org/swgde/documents.html


   
ReplyQuote
(@ac_forensics)
Eminent Member
Joined: 19 years ago
Posts: 44
 

Curtis Rose has a very thorough white paper on Windows IR. Not sure where I got it, but if you give me an email I can send.


   
ReplyQuote
(@cirillop)
Active Member
Joined: 19 years ago
Posts: 14
Topic starter  

Thanks every one, I was looking for a general form a template so to speak and now see that I have to do some more research. But to answer some questions what I am trying to achieve is I have a pure windows shop that consists of a web server located in the DMZ and I wrote a SOP for reviewing the log files for intrusions and one for aquiring a Forensic image. But I would like to write an sop for handling the intrusion all together and thought that an IR sop would best fit.

Hope this helps


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

ac_forensics…could you post the whitepaper you have? I'd be interested in reviewing it.


   
ReplyQuote
(@cirillop)
Active Member
Joined: 19 years ago
Posts: 14
Topic starter  

I would glady do so but I have not started it yet


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Ac_forensics,

Is this what you were referring to
http//web.archive.org/web/20040405032635/http//www.sytexif.com/whitepaper.htm

Harlan


   
ReplyQuote
Page 1 / 2
Share: