Preparing before you need it.
WHY IT MATTERS
Capability cannot be built during an incident.
WHAT TO ESTABLISH NOW
Logging on systems that matter Retention long enough to be useful Centralised collection where possible Time synchronisation across systems An inventory of systems and what they hold
WHY CENTRALISED LOGS
Logs on a compromised system cannot be trusted.
WHY TIME SYNCHRONISATION
Correlating events requires consistent time.
WHAT TO ESTABLISH ABOUT RETENTION
Long enough for delayed discovery.
WHY
Incidents are commonly discovered months after they began.
WHAT TO ENABLE
Authentication logging Administrative action logging Access to sensitive data, where feasible Network connection records
WHAT TO ESTABLISH WITH PROVIDERS
What they log and retain How to request it Who is authorised to request
WHAT TO PREPARE
A procedure for preserving evidence Contacts for specialists Contacts for authorities and regulators Knowledge of notification obligations
WHY CONTACTS IN ADVANCE
Finding them during an incident consumes the time that matters.
WHAT TO ESTABLISH
Who leads an investigation Who authorises it Who communicates
WHAT TO PROVIDE
Basic training for those who would respond first.
WHAT THAT SHOULD COVER
Not to use the affected system Not to delete anything Who to inform How to preserve what they can
WHY THAT MINIMUM
Most evidence is destroyed by the first responder acting reasonably but wrongly.
WHAT TO PRACTISE
The procedure, at least by walking through a scenario.