Knowledgebase

Building Investigative Capability in Advance Print

  • 0

Preparing before you need it.

WHY IT MATTERS

Capability cannot be built during an incident.

WHAT TO ESTABLISH NOW

Logging on systems that matter Retention long enough to be useful Centralised collection where possible Time synchronisation across systems An inventory of systems and what they hold

WHY CENTRALISED LOGS

Logs on a compromised system cannot be trusted.

WHY TIME SYNCHRONISATION

Correlating events requires consistent time.

WHAT TO ESTABLISH ABOUT RETENTION

Long enough for delayed discovery.

WHY

Incidents are commonly discovered months after they began.

WHAT TO ENABLE

Authentication logging Administrative action logging Access to sensitive data, where feasible Network connection records

WHAT TO ESTABLISH WITH PROVIDERS

What they log and retain How to request it Who is authorised to request

WHAT TO PREPARE

A procedure for preserving evidence Contacts for specialists Contacts for authorities and regulators Knowledge of notification obligations

WHY CONTACTS IN ADVANCE

Finding them during an incident consumes the time that matters.

WHAT TO ESTABLISH

Who leads an investigation Who authorises it Who communicates

WHAT TO PROVIDE

Basic training for those who would respond first.

WHAT THAT SHOULD COVER

Not to use the affected system Not to delete anything Who to inform How to preserve what they can

WHY THAT MINIMUM

Most evidence is destroyed by the first responder acting reasonably but wrongly.

WHAT TO PRACTISE

The procedure, at least by walking through a scenario.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot