Attachment 2 - 701-Incident Response Plan 2019.pdf

PDF 2 MB Posted

Attached to
Peace Corps MAC Support Services Federal contract opportunity
Solicitation number
1145PC20Q0022
Issued by
Peace Corps

View the file

Other files for this federal contract opportunity

Other files attached to Peace Corps MAC Support Services, newest first.
File Type Posted
1145PC20Q0022 Final 5.22.20.doc DOC document
Attachment 1 - 209-Vulnerability Management Plan-2019.04_Final.pdf PDF
Attachment 4 - MS 899 Breach Notification Response Plan.docx DOCX document
Attachment 3 - CISA_Incident Reporting Requirements Update _March 29 2019.pdf PDF
Attachment 5 - IPS 1-17 Information Security Program.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Incident Response Plan

January, 2019

Prepared by:

Office of the Chief Information Officer (OCIO)

The Peace Corps

1111 – 20th Street NW

Washington, DC 20526

This page is intentionally blank.

Table of Contents

1 INTRODUCTION

1.1 PURPOSE AND OBJECTIVE

1.2 APPLICABLE REGULATIONS

1.3 SCOPE

1.4 ASSUMPTIONS AND CONSTRAINTS

1.4.1 Assumptions

1.4.2 Constraints

1.5 LIST OF TERMS AND ACRONYMS

2 MODEL AND STRUCTURE

2.1 RELATIONSHIPS AND DEPENDENCIES

3 COMPUTER SECURITY INCIDENT RESPONSE TEAM (CSIRT)

3.1 ROLES AND RESPONSIBILITIES

4 INCIDENT RESPONSE TRAINING

5 INCIDENT RESPONSE TESTING

5.1 UPDATING THE IRP AFTER TESTING

6 COMMUNICATIONS

7 INCIDENT HANDLING

7.1 INCIDENT MANAGEMENT

7.2 PREPARATION

7.2.1 Proactive Tools and Resources

7.3 DETECTION AND ANALYSIS

7.3.1 Detection

7.3.2 Attack Vectors/Sources

7.3.3 Signs of an Incident

7.3.4 Sources of Precursor and Indication Information

7.3.5 Analysis

7.3.6 Identification

7.3.7 Prioritization

7.3.8 Reporting an Information Security Incident

7.3.9 IT Security Investigates and Tracks the Incident

7.3.10 IT Security Reports the Incident to US-CERT

7.4 CONTAINMENT

7.4.1 Evidence Gathering and Handling

7.4.2 Evidence Retention

7.5 ERADICATION

7.5.1 Insider Threats – Intra Organization Coordination

7.6 RECOVERY

8 POST-INCIDENT ACTIVITY

8.1 INCIDENT RESPONSE REPORTING

8.2 LESSONS LEARNED

8.3 METRICS

9 INCIDENT RESPONSE ASSISTANCE

10 PEACE CORPS RECORD RETENTION

APPENDIX A: INCIDENT RESPONSE CALL LISTS

APPENDIX B: DETERMINING CRITICALITY AND SENSITIVITY

APPENDIX C: EXAMPLE SCENARIOS

APPENDIX D: PEACE CORPS INCIDENT RESPONSE REPORT (PC-2049)

APPENDIX E: US-CERT INCIDENT REPORT

APPENDIX F: LESSONS LEARNED DOCUMENTATION

APPENDIX G: CHAIN OF CUSTODY GUIDANCE

List of Tables

Proactive Strategies for Incident Prevention

Incident Identification Methods

Incident Precursors and Indications

US-CERT Reporting Requirements

Impact Category Descriptions .................................................... Error! Bookmark not defined.

Incident Attributes Descriptions ................................................ Error! Bookmark not defined.

NCISS Severity Code

General Incident Recovery Procedures ...................................... Error! Bookmark not defined.

Peace Corps Incident Response Plan

Final January 02, 2019 3

Document Revision History

Revision Description

16.04.27 This is the initial version of this plan based on NIST Special Publication 800-61, DHS

National Cyber Incident Response Plan, FISMA CIO Metrics, and the Peace Corps

Cybersecurity policies. This plan defines the Peace Corps processes, procedures and required resources for managing and responding to all cybersecurity incidents.

17.05.01 Version is in compliance with new US-CERT guidelines to take effect on April 1, 2017.

18.01.02 Version is updated in accordance with the Notice of Findings delivered by the 2017 OIG audit. And, Lessons Learned from Global OCIO IRP Tabletop Exercise on November 2017. Updated US-CERT reporting guidelines.

19.01.02 Version is updated in accordance with the Notice of Findings delivered by the 2018 OIG audit. And, New listed timelines for Federal Civilian Executive Branch entities reporting updates to NCCIC.

Document Approval

Chief Information Security Officer (Effective on receipt of signature & date)

1 Introduction

The Peace Corps is an independent Federal agency under the Executive Office of the President. The

Peace Corps’ mission is to promote world peace and friendship. It provides qualified Volunteers to interested countries in need of trained manpower to foster a better understanding of Americans by the people served, and foster a better understanding of those people served by Americans. The Peace

Corps provides assistance at the grassroots level and through cross-cultural exchange. Headquartered in

Washington, D.C., it currently has eight (8) Regional Recruiting Offices (RROs) within the United States and approximately seventy (70) overseas posts serving seventy-five (75) countries.

As an executive agency with a global Information Technology (IT) infrastructure, the Peace Corps is required to meet Federal guidelines for securing information and information technologies. The Chief

Information Officer (CIO) and the Chief Information Security Officer (CISO) are responsible for agency-wide IT security oversight and compliance.

Incident Response (IR) is an important component of risk management for organizations that transmit sensitive information over a network. Security-related threats are numerous, diverse, and disruptive to daily operations. New types of security-related incidents occur frequently. In addition, lost data, lost business functionality, and lost time due to investigations, cost organizations valuable resources. Risk-based preventative activities can lower the number of, but not prevent, incidents, even for institutions willing to expend unlimited resources.

IR is a coordinated, cohesive approach to computer security and the agency’s level of preparedness that determines the effectiveness of the IR strategy.

1.1 Purpose and Objective

In accordance with the Federal Information Security Management Act of 2002 (FISMA), Federal agencies must document activities taken to enforce written policies and prevent, mitigate, detect, and respond to incidents. FISMA also requires an Incident Response capability for preventing propagation of the incident and restoring computing services.

Thorough planning significantly reduces response time, downtime, and overall impact when an incident occurs. This Incident Response Plan (IRP) incorporates lessons learned from previous incidents to improve and update policy and procedures, and mitigate exploited weaknesses.

This IRP provides a source for the Computer Security Incident Response Team (CSIRT) to identify, contain, and recover from IT security incidents, such as virus attacks, spyware, unauthorized use, loss or theft of Government Furnished Equipment (GFE) that contains Government Data and/or User PII information, password compromise, data theft, and web site defacement.

1.2 Applicable Regulations

This IRP complies with IPS 1-17 Information Security Program. In addition, the IRP meets the following regulations and guidelines:

The Federal Information Security Management Act of 2002 (FISMA), as Title III of the E-

Government Act of 2002.

Federal Information Security Modernization Act of 2014, Public Law 113-283, chapter 35 of title

44, United States Code (U.S.C.).

Office of Management and Budget (OMB) Circular No. A-130 Revised, Appendix III, Security of

Federal Automated Information Resources, November 2000.

OMB Memorandum M-06-16, Protection of Sensitive Agency Information, June 23, 2006.

OMB Memorandum M-06-19, Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments, July 12, 2006.

OMB Memorandum M-16-03, Fiscal Year 2015-2016 Guidance on Federal Information Security and Privacy Management Requirements, October 2015.

OMB Memorandum M-16-04, Cybersecurity Strategy and Implementation Plan (CSIP) for the

Federal Civilian Government, October, 2015.

OMB Memorandum M‐17‐09, Management of Federal High Value Assets, December 2016.

OMB Memorandum M‐17‐25, Reporting Guidance for Executive Order on Strengthening the

Cybersecurity of Federal Networks and Critical Infrastructure, May 2017.

National Institute of Standards and Technology (NIST) Federal Information Processing Standards

Publication (FIPS), Publication (PUB) 200, Minimum Security Requirements for Federal

Information and Information Systems, March 2006.

National Institute of Standards and Technology (NIST) Federal Information Processing Standards

Publication (FIPS), Publication (PUB) 199, Standards for Security Categorization of Federal

Information and Information Systems, February 2004.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-12, An

Introduction to Computer Security: The NIST Handbook, October 1995.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, Guide for

Applying the Risk Management Framework to Federal Information Systems February 2010.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Revision

4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, April 2006.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-61, Computer

Security Incident Handling Guide, January 2004.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-83, Guide to

Malware Incident Prevention and Handling, November 2005.

National Institute of Standards and Technology (NIST) Special Publication 800-86, Guide to

Integrating Forensic Techniques into Incident Response, August 2006.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-100, Information Security Handbook: A Guide for Managers, June 2006.

NIST Special Publication 800-137, Information Security Continuous Monitoring (ISCM) for Federal

Information Systems and Organizations, September 2011.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-184, Guide for

Cybersecurity Event Recovery, December 2016.

Manual Section MS 899, Breach Notification Response Plan. Policies and procedures of the

Agency’s Breach Notification Response Plan (Breach Plan), January 28, 2013.

Manual Section MS 511, Personal Property Management Handbook, Procedures to account for

Peace Corps property, Updated September 2017.

Interim Policy Statement IPS 1-17, Information Security Program, Information Security for the

Peace Corps information systems, June 16, 2017.

National Institute of Standards and Technology (NIST), Framework for Improving Critical

Infrastructure Cybersecurity Draft Version 1.1, February 2014.

United States Computer Emergency Readiness Team (US-CERT) Federal Incident Notification

Guidelines, April 2017.

Presidential Policy Direction (PPD) 41, United States Cyber Incident Coordination, July 2016.

1.3 Scope

This document contains the incident response and reporting process that applies to the Peace Corps systems, information, and environments. This document provides incident response and escalation procedures for the Peace Corps Incident Response program. Particularly, lower-level system components (i.e., individual Peace Corps systems) may be addressed by system specific incident response procedures. During the absence of the system specific incident response procedures, this document will take the place of the system specific incident response procedures and will apply to all

Peace Corps personnel.

1.4 Assumptions and Constraints

The following assumptions and constraints apply to this document.

1.4.1 Assumptions

Memorandums of Understanding (MOU) or Statements of Work (SOW) have been established between Peace Corps systems and the appropriate supporting help desks.

This document does not discuss preventive measures, neither the efficacy of specific security and privacy controls.

This document will continue to be updated annually to remain accurate and useful.

This document covers the unclassified network only.

1.4.2 Constraints

The scope of this document extends to the systems under the direct control of the

Peace Corps; although it discusses interactions with other entities, this document is not applicable to non-Peace Corps controlled data centers, or other facilities.

1.5 List of Terms and Acronyms

The following list defines acronyms and terms used throughout this IRP.

Acronym Definition Acronym

AO Administrative Officers AO

ATO Authorization to Operate ATO

BRP Business Recovery Plan BRP

CD Country Director CD

CDM Continuous Diagnostics and Mitigation CDM

CIO Chief Information Officer CIO

CIRC Cybersecurity Incident Response Coordinator CIRC

CISO Chief Information Security Officer CISO

COOP Continuity of Operations Plan COOP

CR Change Request CR

CSIRT Computer Security Incident Response Team CSIRT

DHS Department of Homeland Security DHS

DMZ Demilitarized Zone DMZ

Acronym Definition Acronym

DOS Denial of Service DOS

DRP Disaster Recovery Plan DRP

EA Enterprise Architecture EA

EAP Emergency Action Plan EAP

E-mail Electronic mail E-mail

FIPS Federal Information Processing Standard FIPS

FISMA Federal Information Security Management Act FISMA

GFE Government Furnished Equipment GFE

GFIRST Government Forum of Incident Response and Security Teams GFIRST

GSS General Support System GSS

HIDS Host Intrusion Detection System HIDS

ICS Industrial Control Systems ICS

IP Internet Protocol IP

IR Incident Response IR

IRC Incident Response Coordinator IRC

IRP Incident Response Plan IRP

ISP Internet Service Provider ISP

ISS International Support & Services ISS

ISSM Information System Security Manager ISSM

ISSO information system security officer ISSO

IT Information Technology IT

ITS International Technical Support ITS

MA Major Applications MA

MAC Media Access Control MAC

MBR Master Boot Record MBR

MOU Memorandum of Understanding MOU

MS Manual Section MS

NIDS Network Intrusion Detection System NIDS

NIST National Institute of Standards and Technology NIST

OGC Office of General Counsel OGC

OIG Office of Inspector General OIG

OMB Office of Management and Budget OMB

PCHQ Peace Corps Headquarters PCHQ

PCII Protected Critical Infrastructure Information PCII

PHI Personal Health Information PHI

PII Personally Identifiable Information PII

POA&M Plan of Action and Milestones POA&M

POC Points of Contact POC

RA Risk Assessment RA

RITS Regional IT Specialists RITS

RRO Regional Recruiting Office RRO

SA System Administrator SA

SAT Security Assessment Test SAT

SIEM Security Incident Event Management (Security Analyst) SIEM

SLA Service Level Agreement SLA

SME Subject-Matter-Expert SME

SOC Security Operations Center SOC

Acronym Definition Acronym

SP Special Publication SP

SSP System Security Plan SSP

URL Uniform Resource Locator URL

US-CERT United States Computer Emergency Readiness Team US-CERT

VPN Virtual Private Network VPN

2 Model and Structure

The Peace Corps’ governance structure is based on Federal, DHS, NIST and OMB policy guidance. It provides a policy based process to ensure that the organization has user agreements, rules of behavior, periodic information assurance training and role based training to provide a cybersecurity aware workforce. This helps reduce the number of security incidents and hold responsible violators who create security incidents.

Specifically, the workforce is made aware and reminded of the responsibility of reporting incidents as a user of the Peace Corps information resources.

The Continuous Diagnostics and Mitigation (CDM) program also ensures Peace Corps is in compliance with the Federal, DHS, NIST and OMB policy guidance, especially security controls based on NIST 800-

53r4, requiring these reportable and auditable activities regarding personnel, annual security training, agreements and role based training. These security controls also drive the level of management, operation, and technical protection to harden against security incidents.

The OMB and NIST policies and procedures drive the incident response plan. Peace Corps recognizes that the response resources are limited and incidents must be triaged based on the severity (of elements: Functional Impact, Information Impact, and Recoverability) and risk rationale to assign the existing resources efficiently and resolve the incidents promptly.

The IR model uses a centralized approach with an Incident Response Coordinator (IRC) for the gathering of the initial incident information, and the Cybersecurity Incident Response Coordinator (CIRC) designated as the IR Program single point-of-contact for all incidents.

International Technical Support (ITS) staff and the OCIO Domestic Service Desk staff play a pivotal role, serving as local IRC’s, gathering initial incident information. The term IT Specialist is used interchangeable to refer to both domestic and Overseas IT staff.

The Regional IT specialists (RITS) provide 24 coverage to POSTs. This team of IT Specialists are the liaison between the IT Specialists (ITS) and the CIRC located in headquarters. RITS provide support to the local

IT Specialists, assist with the containment and mitigation procedures, and ensure the prompt notification to HQ to meet the CISA time guidelines. For domestic support, the “Manager of domestic support services” has designated a liaison for the domestic Helpdesk that meets the same standards as

RITS performs at POSTs.

The CIRC is responsible for incident handling, reporting incidents to US-CERT, coordinating actions with the Incident Response Team(s) (CSIRT) , and reporting across the agency. The CIRC establishes an ad-hoc CSIRT of Subject-Matter-Experts (SME’s), IRCs and business office POCs. CSIRT members report to the CIRC for the duration of the incident. Team members vary depending on the nature, scope, and complexity of the incident. Specifically, the CIRC is responsible for reporting and provides status updates to the CIO and the CISO.

2.1 Relationships and Dependencies

Business Continuity - Extended incidents impact disaster recovery or continuity of operations.

Business continuity processes must be in sync with IR policy and procedures.

Human Resources - Counseling or disciplinary actions may be necessary for employees involved in the incident.

IT Security - IT security personnel are usually the first to identify and respond to events and must include a CIRC to ensure planning, coordination and lessons learned are up to date.

Production Operations and Infrastructure - The IT support group is often consulted and used to support the CSIRT, as they are technically adept and knowledgeable of systems, networks, and daily operations.

General Counsel - The impact of the incident may result in consultation with legal counsel regarding prosecution of the perpetrators and steps to minimize liabilities resulting from the incident.

Executive Management - Leaders provide guidance, budget approval, and resources necessary to implement, and perform Incident Response.

Safety and Security - Access to buildings and computer spaces involve physical security managers; in addition, some incidents begin or are executed via physical access to computer systems. Coordination is vital for a prompt, effective response and investigation.

Communications - Public affairs or media relations may be consulted and informed during the response, eradication and restoration of services.

Cyber Security Expert Support - The CISO maintains the authority to involve any third party forensics expert, while the CIRC provides oversight of evidence collection as needed.

Information systems-focused plan that may activate an Information System Contingency Plan (ISCP) or

Disaster Recovery Plan (DRP) depending on the extent of the attack.

Information System Contingency Plan (ISCP) – Provides procedures and capabilities for recovering an information system. The plan scope addresses single information system recovery at the current, or if appropriate alternate location.

Disaster Recovery Plan (DRP) – Provides procedures for relocating information systems operations to an alternate location. The scope of the plan is to be activated after major system disruptions with long-term effects.

Final January 02, 2019 12

3 Computer Security Incident Response Team (CSIRT)

During an incident that creates “major” functional and information Impacts, and recoverability; the

Peace Corps CSIRT serves as the first tier in handling incidents occurring within Peace Corps system boundaries. The Peace Corps CSIRT assists the reporting party (for example, system administrator, network administrator, or user) during the incident handling process.

Section 6 documents the detailed roles and responsibilities for the CSIRT. Additionally, the Peace Corps

CSIRT contact information can be found in Appendix A. In the cases of systems and environments hosted by other agencies or organizations, it is possible that the Peace Corps OCIO Domestic Service

Desk or helpdesk and the Peace Corps CSIRT will need to interact with other agency help desks or

Security Operations Centers (SOCs) (e.g., Department of State Help Desk).

3.1 Roles and Responsibilities

The following table summarizes incident response roles and responsibilities.

Table 1. Incident Response Roles and Responsibilities

Role Responsibilities

Users Report incidents immediately to Service Desk, ITS, and/or IT Security upon recognition or suspicion of an incident.

Document all relevant details of incident.

Provide all documentation associated to the incident (e.g. Police report)

OCIO Service Desk

(Domestic and/or Overseas)

Open a ticket and assign it to Cyber Security team queue and notify CIRC.

Assist End User with the completion of Section I of the Incident Security Response Report – form PC-2049.

Send email notifications per the established procedure.

Provide technical assistance during an incident.

Establish and implement tools and processes supporting the Peace Corps Service desk policies and procedures to ensure containment, mitigation and timely reporting of security incidents.

Overseas IT Specialists contact RITS(s) and requests assistance, escalates and/or notifies incidents for better detection and analysis of the event.

Obtain information from Production Operations & Infrastructure and create a problem ticket where applicable.

IT Specialist (Domestic and/or Overseas) becomes the Incident Response Coordinator (IRC).

Role Responsibilities

Incident Response Coordinator (IRC)

Manages the local response, collects, and reports elements of the incident.

Communicates and reports to CIRC as stipulated.

Coordinate the local activities and coordinates efforts with the CSIRT, tracks the status of the incident and provides updates through incident reports until resolution.

Documents and preserves (with sufficient details the audit trail) the actions taken to investigate an event or incident.

Documents post-level incident activities and lessons learned.

Serve as the local presence for the security incident response.

Inform and escalates incidents to RITS, CIRC and management at

POST.

Role Responsibilities

Cybersecurity Incident Response Coordinator (CIRC)

Serve as the Global Cybersecurity Incident Response Coordinator (CIRC) unless directed otherwise.

Manage the overall Incident Response Program.

Evaluate past events and incidents for trends and patterns.

Monitor Cyber Security ticket queue and respond to potential incidents.

Assess reported incidents and determine the appropriate course of action.

Notify to US-CERT reportable incidents including the Impact Category Descriptions and associated severity levels (based on elements: Functional Impact, Information Impact, and Recoverability) and risk rationale.

Coordinate with IT Security Training Manager regarding cyber security education matters.

For latest and/or major Incidents:

Assemble the ad-hoc CSIRT, identifying technical expertise needed based on initial reports and systems impacted.

Communicate with the Service Desk (Domestic and/or Overseas) to monitor (detection and analysis of) the incident and associated impacts.

Notify to US-CERT including the Impact Category Descriptions and associated severity levels (based on elements: Functional Impact, Information Impact, and Recoverability) and risk rationale.

Communicate with business POCs, ISSMs and system owners based on the nature, location or severity of the incident.

Track the status of the incident (containment, eradication, recovery) through incident reports until resolution.

Keep the CIO and the CISO informed of the incident status.

Frequency is determined by the severity and criticality of incident.

Update status as required to US-CERT.

Facilitate actions and notifications with Management, OGC and OIG as necessary.

Role Responsibilities

Computer Security Incident Response Team (CSIRT)

Is organized for the Containment, Investigation, Eradication, and Recovery of an incident. SCIRT is assembled when additional response resources are required in response to an incident.

CSIRT is called up by the CIRC in coordination with the CISO and CIO.

Perform incident evaluation, handling, and recovery operations.

Act as the primary resource providing support through the incident handling stages.

Establish and implement tools and processes supporting the Peace Corps and/or US-CERT policies and procedures to ensure timely triaging reporting of security incidents.

Serve as the 1st tier incident response capability at the Peace Corps level.

Security Incident Event Management (SIEM) Security Analyst

Examine and report Incident Cases indicated by AlienVault SIEM system.

Provide SME support in triaging the reported security incidents.

When called upon serve as the security support of CSIRT.

ISSM/ISSO/System Owner Provide leadership and guidance on developing the system specific incident response procedures.

Together with the CIRC/CSIRT, determine whether an incident is a reportable incident to US-CERT.

Inform Authorizing Official of the incident and assist in development of course-of-action.

Senior Accountable Official for Privacy

Responsible for compliance with Federal Privacy laws at the Peace Corps organizational level.

Coordinate with the CIRC, General Counsel and IG providing guidance to Peace Corps personnel regarding matters involving PII and data breach.

POC for the Data Breach Response Team.

CIO Authorize the CSIRT as the 1st tier incident response and the investigative and reporting body.

Responsible for the Peace Corps Incident Response Program.

Inform the Peace Corps Director and Risk Executive of the incident.

CISO Authorize the CSIRT as the 1st tier incident response and the investigative and reporting body.

Responsible for the Peace Corps Incident Response Program.

Enforce the Federal incident handling processes and procedures in compliance with applicable FISMA, OMB, and DHS guidelines.

Ensure that US-CERT reportable incidents are submitted within reporting time requirement.

Inform the Peace Corps Director and Risk Executive of the incident.

Final January 02, 2019 17

4 Incident Response Training

All Peace Corps staff and contractors must receive Security Awareness Training (SAT) upon hire, and pass a refresher course and examination annually thereafter. The agency may identify the need to implement refresher training outside of the routine schedule, if needed to reinforce practices following a security breach. Security awareness training will include adequate training to recognize a potential incident and instructions for reporting incidents. Real-world examples will be included as part of each session and examination.

Additional training sessions will be customized for system administrators, ISSMs, and designated

Incident Responders. As each role dictates, the training will be structured to provide the knowledge and skills necessary to recognize and manage Incident detection, analysis, forensics, remediation, and restoration strategies.

The CIRC will incorporate lessons learned and any new tools, techniques, staffing resources, and federal mandates into the training sessions to ensure consistent use across the agency.

The CISO is responsible for ensuring proper resource allocation to include budgeting, scheduling and staffing necessary to conduct the requisite training.

Training

Final January 02, 2019 18

5 Incident Response Testing

The CIRC will plan and conduct Incident Response tabletop activities to verify that the response procedures produce the expected outcome. The exercises are scheduled once a year and participants will, throughout the exercise, validate the processes and procedures of the Plan. The test scenarios will be based on incidents most likely to occur and lessons learned from previous exercises.

The Peace Corps’ emergency response, recovery, and restoration practices are documented in Disaster

Recovery Plans, the Continuity of Operations Plan (COOP), and the Safety and Security Evacuation Plan.

However, the following list outlines the Incident Response testing activities that must take place to meet

FISMA requirements.

1. The CIRC must work with the individuals responsible for other related agency plans, such as the IT

Disaster Recovery (DR) Plan, the Continuity of Operations Plan (COOP), Emergency Action Plan (EAP), Business Recovery Plan (BRP) and/or the Business Impact Assessment (BIA) to ensure synchronicity between the Incident Response Plan and other agency response and recovery plans.

2. The CIRC must coordinate with the ISSMs and the System Owners.

The frequency of testing is dependent on the interval between major changes in the hardware and software environments.

Testing procedures may include both team-specific and cross-team training exercises, spanning orientation, tabletop, and functional methods.

3. The CIRC is responsible for the development and implementation of the Incident Response Test

Plan.

4. The CIRC must develop and maintain a calendar that includes the schedules for Incident Response

Plan testing.

5.1 Updating the IRP after Testing

1. The CIRC will prepare a report for the CIO and the CISO detailing the test results in terms of Peace

Corps’ readiness to execute the Incident Response Plan, recommendations for corrective actions, and lessons learned.

2. The CIRC must ensure that the Incident Response Test Plan is reviewed and updated at least annually.

3. The Incident Response Plan update procedure must follow the Peace Corps formal review process per MS-542 Peace Corps IT Security Policies and Procedures.

Final January 02, 2019 19

6 Communications

An effective CSIRT maintains communication and keeps the right people informed of events and incidents. Notification and activities related to resolving any incidents are also dependent upon the effective communication of essential tasks. Follow-on contact responsibilities for each role during a

Computer Security Incident Response are included in the Roles and Responsibilities chart in Section 3.

If the Incident needs escalation outside of the agency, other than to the United States Computer

Emergency Readiness Team (US-CERT), or the US-CERT Government Forum of Incident Response and

Security Teams (GFIRST), the CISO will initiate an external communication plan as needed. No one in the agency, including the CSIRT members, should communicate with members of the press or law enforcement agencies without prior coordination through the CISO with the Peace Corps General

Counsel and/or Communications Division.

Final January 02, 2019 20

7 Incident Handling

NIST SP 800-61 separates IR activities into five phases: Preparation, Detection and Analysis, Containment, Eradication, and Recovery. IR activities may occur independently or in combination with other phases. These activities work well for most technical incidents, but may require adapting to address a HIPAA privacy incident, PII incident, or an information disclosure complaint.

Incidents are recorded and tracked in the Peace Corps Track-It! ticketing system. Each Service Ticket is assigned a Service/Incident Ticket Number, and will contain all details, status, reports, and attachments

(if required) associated with current and historical records.

The IRC (local IT Specialist domestic and overseas) reports the incident using the Information Security

Incident Response Report (PC-2049), which is attached to the Service Ticket record in Track-It!. IRC assists the user, who reports the event, to complete Section I of the PC-2049 form.

RITS assist with containment and mitigation actions. Based on the evidence, RITS (domestic and overseas) complete sections: II Incident Containment, III Investigation/Conclusion, and IV Resolution of the PC-2049 form.

The CIRC updates PC-2049, reviews section IV Resolution, and completes section V Reporting. If closure is satisfactory, the form is signed.

If required, CIRC will assemble the ad-hoc CSIRT, identifying technical expertise needed based on initial reports and systems impacted. CIRC will notify to US-CERT and will provide Impact Category Descriptions and associated severity levels (based on elements: Functional Impact, Information Impact, and

Recoverability) and risk rationale within one hour of the Incident being confirmed. CIRC facilitates actions and notifications with Management, OGC and OIG as necessary.

PII paper breaches are not reportable to US-CERT unless it includes digital data. And, per MS-899, all paper breaches must be handled internally.

When transferring physical evidence to other offices or agencies as part of the investigation, the CIRC must record and track transfers using Form PC-2125, the Incident Investigation Chain of Custody Form;

and attach PC-2125 to the service ticket.

As part of incident closure, the CIRC documents the resolution in the report and closes the service ticket.

Data Breach handling process.

7.1 Incident Management

This Incident Response Plan includes the agency’s standard operating procedures for computer security

Incident Response, vulnerability analysis to mitigate weaknesses, and the restoration of Peace Corps IT systems. The plan establishes the following guiding principles for latest or new trends of reported incidents. The agency’s IR strategy addresses the following:

Identifies procedures for performing incident handling and reporting, Lists the requirements for reporting incidents, Identifies staff and CSIRT training requirements, Identifies appropriate structure and staffing models for the Incident Response Team, Defines the roles and responsibilities of CSIRT members, Establishes communication and cooperation guidelines between the CSIRT and other internal groups (i.e., GC and IG), and

Establishes communications and cooperation between the CSIRT and external groups (e.g., US-

CERT, GFIRST, and law enforcement agencies).

1. For each incident, the Cybersecurity Incident Response Coordinator (CIRC) will serve as the single point-of-contact unless otherwise assigned. The CIRC is responsible for ensuring that the required incident reporting, including reports to the US-CERT, are prepared and submitted. CIRC also facilitates actions and notifications with Management, OGC and OIG as necessary.

The IRC is responsible for the triage of the incident prioritization by following stablished guidelines, and by providing an effective and timely escalation response to cyber events or incidents.

2. CIRC, CSIRT and other individuals will implement the incident prioritization guidelines to provide effective and timely response to cyber events or incidents.

3. The CIRC must ensure that US-CERT Reporting Timeframes defined on the US-CERT site are met.

4. The CIRC must ensure the Incident Response Plan provides clear criteria for categorizing observable occurrences as events or incidents.

An event is any observable occurrence in an IT system that may have IT security implications.

Events include suspicious or out-of-the-ordinary attempts by a user to connect to a file share, a server receiving an unauthorized request for a Web page, a user sending unauthorized electronic mail (E-mail), and the firewall blocking a connection attempt.

An incident is any event that threatens the availability, integrity, and confidentiality of information resources. Incidents are events that could lead to negative consequences, such as

IT system crashes, Denial of Service (DOS) attacks, unauthorized use of IT system privileges, defacement of a Web page, and execution of malicious code that compromises or destroys data.

5. The CIRC must coordinate with the Office of Safety and Security (OSS) to ensure the Incident

Response Plan addresses physical IT security events or incidents such as those discovered as part of monitoring physical access to areas with IT systems.

6.

7.2 Preparation

Preparation is the key to effective Incident Response and prevention. Emphasis on preparation ensures the agency is ready to respond to incidents, nevertheless has already taken the necessary steps to prevent incidents by securing systems, applications, and networks. Organizations are better prepared to respond to an incident when they:

Use proactive techniques to prevent incidents;

Establish a formal Incident Response Team;

Develop an emergency Communications Plan; and

Conduct routine education and training for team members.

7.2.1 Proactive Tools and Resources

Proactive techniques are employed to prevent the occurrence of an incident within an organization.

These techniques can reduce, but not eliminate, the chance an incident will occur. The following proactive techniques can ultimately reduce an Incident’s impact on the Peace Corps. These proactive techniques are built into the Peace Corps IT operations, provided in the annual security training, and other IT Security awareness activities.

Proactive Strategies for Incident Prevention

Techniques Description

Anti-virus and Encryption Ensuring all servers, desktops, laptops, and mobile devices have Antivirus capabilities and virus definition tables are up-to-date.

Encryption ensures that data remains secure

User Awareness & Training Ensuring all system users are informed of potential impact as a result of a virus, worm, ransomware, and other outbreaks attacks. Training allows users become familiar on how to report suspected incidents to the appropriate office.

Email Client Configuration Ensuring email clients are configured to not automatically open attachments.

Intrusion Detection System (IDS) and Vulnerability Scanning

An intrusion detection system (IDS) is a device or software application that monitors network or system activities for malicious activities or policy violations and produces reports to a management station.

Vulnerability/Patch Management

Implementing an effective method to address known system vulnerabilities.

7.3 Detection and Analysis

An incident can be detrimental to Peace Corps’ daily operations; it could also impact its reputation. In the early stages of an event, the exploited vulnerability may not be known. This could allow a subsequent “copy-cat” type of attack, and/or an extension of the first event to occur.

Revealing details about the ongoing situation could result in further exploitation of Peace Corps systems or services. Adverse publicity can make the incident more difficult to manage. Finally, what one individual or organization perceives as a “major” problem, might in fact, only be a minor incident (or merely an event). Therefore, the Detection and Analysis phase of IR is critical to clearly identifying, classifying, and successfully resolving an Incident.

7.3.1 Detection

Identifying incidents is a challenging task. They often occur due to an accidental configuration, or through deliberate actions of internal or external individuals. Identification requires Peace Corps to understand detection and analysis techniques in order to direct the appropriate response activities.

Identification is best accomplished using a combination of methods. These methods for discovering and confirming incidents are classified into three categories: Routine Monitoring, Investigation, and

Reported. See Table 2 below.

Incident Identification Methods

Identification Method

Definition

Routine

Monitoring

Routine Monitoring are actions performed regularly, such as audit log reviews and network resource monitoring. Routine Monitoring methods represent many of the proactive elements of Incident Response.

Investigation This method is used to identify incidents that occur infrequently, or at random.

Examples include investigations of unusual trends or peculiar events, such as excessive attempts to ping the network, or recurrent intrusion detection alerts.

Reported Reported problems may also lead to the detection of incidents. User complaints of slow connectivity, or denial of service such as the inability to transmit, may uncover an incident. Another example of reported problems indicative of an incident is workstation issues related to a virus.

7.3.2 Attack Vectors/Sources

It is not possible to define and prepare for every type of incident; however, this section lists the common attack vectors that are considered when planning the strategy for detecting and handling incidents (Note: This category is no Longer Required since April 1st, 2017. This section is included as a reference).

Unknown: Cause of attack is unidentified.

Example: This option is acceptable if cause (vector) is unknown upon initial report. The attack vector may be updated in a follow-up report.

Attrition: An attack that employs brute force methods to compromise, degrade, or destroy systems, networks, or services

Example: Denial of Service intended to impair or deny access to an application; a brute force attack against an authentication mechanism, such as passwords or digital signatures.

Web: An attack executed from a website or web-based application.

Example: Cross-site scripting attack used to steal credentials, or a redirect to a site that exploits a browser vulnerability and installs malware.

Email/Phishing: An attack executed via an email message or attachment

Example: Exploit code disguised as an attached document, or a link to a malicious website in the body of an email message.

External/Removable Media: An attack executed from removable media or a peripheral device

Example: Malicious code spreading onto a system from an infected flash drive.

Impersonation/Spoofing: An attack involving replacement of legitimate content/services with a malicious substitute.

Example: Spoofing, man in the middle attacks, rogue wireless access points, and structured query language injection attacks all involve impersonation.

Improper Usage: Any incident resulting from violation of an organization’s acceptable usage policies by an authorized user, excluding the above categories.

Example: User installs file-sharing software, leading to the loss of sensitive data; or a user performs illegal activities on a system.

Loss or Theft of Equipment: The loss or theft of a computing device or media used by the organization.

Example: A misplaced laptop or mobile device.

Other: An attack that does not fit into any of the other categories.

7.3.3 Signs of an Incident

The most challenging part of the IR process is accurately detecting and assessing incidents. This includes conclusively determining whether an incident has occurred. If an event is deemed an incident, a combination of three factors - type, extent, and magnitude - are used to assess the event.

Incident types are generally determined and classified by the level of detail available to local IT staff. Manual detection of an incident includes the reporting of a privacy complaint or a vague operational complaint from one or more users. Another level of detail includes automated network-based and host-based sensors, antivirus software, and log analyzers. The volume of incident signs is typically high when using an automated detection system.

For example, it is not uncommon for an organization to receive thousands or even millions of intrusion detection sensor alerts per day.

The extent of an incident generally relates to the number of users, workstations, servers, networks, sites, and/or business services impacted by an incident.

The magnitude and extent of an incident also may be discovered by manual or automated means.

Proper and efficient analysis of incident-related data normally requires deep, specialized technical knowledge and extensive experience.

Signs of an incident fall into one of two categories: precursors and indications. A precursor is a sign that an incident may occur in the future. An indication is a sign that an incident may have occurred or may be occurring now.

The CSIRT evaluates incidents and potential instances using the following types of information:

Network intrusion detection sensor alerts, Antivirus software alerts, User complaints, Discovery of unusual files, A spike in service desk tickets, Unusual events recorded in audit logs, Unusual deviation from typical network traffic flows, and

Unexplained loss of functionality distributed in unusual patterns or numbers.

7.3.4 Sources of Precursor and Indication Information

Precursor and indication incident signs are derived from a variety of sources within the IT infrastructure.

Commonly, the sources consist of security software alerts, audit logs, outside sources (www.cert.org), and people internal and external to the IT department. While received independently, they are used in combination to identify and detect a true incident. The Peace Corps also employs a third party monitoring contractor to ensure independent assessment of any precursor information at headquarters.

Peace Corps systems evaluate the sources of precursors and indications found in Table 3 as part of the incident detection and analysis process.

Incident Precursors and Indications

Source Description

Computer Security Software Alerts

Network Based IDS

(Smart Defense)

IDS products identify suspicious events and record pertinent data, including the detection date and time, type of attack, source and destination IP addresses, and username(s) (if applicable and known).

Peace Corps systems currently use a Security Incident and Event

Management (SIEM) tool. All alerts from the SIEM are evaluated by the SOC to ensure validity. This prevents the CSIRT from responding to a false positive.

Source Description

Antivirus Software Antivirus products are effective at detecting, eradicating, or isolating malicious code - provided their signatures are current. Commercial

Off The Shelf (COTS) products typically send alerts to the affected host and a centralized antivirus console (when configured). The

CSIRT uses antivirus software. All antivirus alerts reported by users are evaluated by the SOC to determine the type and extent of the infection.

Audit Logs

Operating System and

Application Logs

Logs from operating systems, services, and applications (particularly audit-related data) are frequently of great value when an incident occurs. Logs provide a wealth of information, such as which accounts were accessed and what actions were performed. These logs are used by the CSIRT to gather incident documentation and determine appropriate response and recovery activities.

IT Specialists, as IRCs, may review the logs, report the analysis to the

Service Desk, and escalate the incident as appropriate.

Network Device Logs Logs from network devices such as firewalls and routers are also valuable in identifying trends (e.g., a significantly increased number of attempts to access a particular port) and correlating events detected by other devices. The CSIRT reviews these logs in conjunction with other signs and evaluates if a true incident occurred and, if so, the scope of the incident.

IT Specialists at posts may review the network device logs and report the information to the ITS Desk and the CIRC, as appropriate.

Publicly Available Information

US-CERT Coordination

Center

Keeping up with new vulnerabilities and exploits can prevent some incidents from occurring and assist in the detection and analysis of new attacks. Organizations, such as the US-CERT Coordination

Center periodically provide threat update information through briefings, web postings, and mailing lists. The CSIRT uses readily available security information from the US-CERT Coordination Center to prepare and detect potential incidents. http://www.us-cert.gov.

People http://www.us-cert.gov/

Source Description

Peace Corps Personnel Users, system administrators, network administrators, security staff, and others from within the organization may report signs of incidents. The CIRC will review the reported signs and determine whether the CSIRT should be activated. If activated, the CSIRT validates the incident(s) to ensure that appropriate response measures are taken.

Outside Peace Corps Normally, few incident reports originate from other organizations.

However, important external sources of incident information are listed below. Each of these maintain some level of connectivity to the network infrastructure :

US Treasury

NFC

Peace Corps posts

Website Users

Other interconnections

The HIPAA Security Rule mandates the reporting of incidents by

Business Associates. A Business Associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity. The CIRC will evaluate incidents or suspected incidents reported from external sources and provide a status update to the CISO.

7.3.5 Analysis

Precursors or indications are not always accurate predictors of events. For example, end user-provided indications such as complaints about server availability are often incorrect. Intrusion detection systems are known to produce large numbers of false positives and incorrect indications. These examples demonstrate the difficulty of incident detection and analysis: each indication should be evaluated to determine if it is legitimate. The sheer volume of indicators further complicates the situation. The total number of indicators, from human and automated sources, may be thousands or millions a day.

7.3.6 Identification

Identifying incidents is a challenging task. They often occur due to an accidental configuration, or through deliberate actions of internal or external individuals. Identification requires Peace Corps to understand detection and analysis techniques in order to direct the appropriate response activities.

Identification is best accomplished using a combination of methods. See table 2 above.

7.3.7 Prioritization

Incident analysis by the CSIRT involves the review and analysis of signs to determine the scope and impact to Peace Corps systems. Criteria to analyze an incident include:

Is this a multi-site incident?

How many computers/systems are compromised?

Is the compromised computer/system critical?

Do any other critical computer/systems trust the compromised computer / system?

Is sensitive information held on the compromised computer/system?

Do user accounts on the compromised computer/system have rights within other systems or applications?

Do the compromised computers/systems have network shares with any other computer/system?

Answers to these criteria help establish an…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .