No business-continuity plan is complete without a computer SWAT team to protect systems from a multitude of disruptions.
|
Before you declare your business-continuity planning complete, ask yourself this: What happens when the alarm sounds, be it for a natural disaster, a power grid failure or a security breach? If you don’t have people trained and ready to respond, no matter the situation, then you won’t be as prepared as you ought to be. What you need is an incident response team, one that has dedicated resources and coordinated processes, say business-continuity experts.
Those who have already adopted formal internal IRTs say the benefits run deep. “Many people think that incident response is reactive mode, but a good IRT will work to protect the network and to avoid incidents – and if they cannot be avoided, to react quickly and effectively,” says Mario Chiock, global manager, Incident Response Team, for oil field services company Schlumberger, in Houston.
Other experts say an IRT keeps a company’s options open. “Think of this as a fire department. Putting out the fire is part of it, but they also have to research the aftermath,” says Julie Lucas, an IRT director for a Fortune 500 financial services company and author of The Effective Incident Response Team.
A trained team will give the company systematic analysis so it can determine the who, what, when, where and why of an incident, Lucas says. If an incident is security related, the team also will collect and preserve evidence needed for potential prosecution.
Building an IRT needn’t be grueling. It involves designating appropriate personnel, ensuring proper training, and implementing reporting and tracking procedures.
Because IRTs help ensure that necessary IT systems stay available under all conceivable circumstances, they should be staffed with “a mix of talents,” Lucas says. Most team members would be from IT, representing various technology skills. But a capable team would include general project managers to assist with critical business issues; corporate counsel, should a breach lead to law enforcement actions or affect customer contracts; corporate communications representatives, for handling discussions with the public, press or customers; human relations managers, for communicating with employees; and physical security specialists, for securing buildings or removing suspect employees. Each team would have roles for a company’s specific needs or the incident at hand.
Dynegy has woven IRTs into its crises management processes, which are part of a bigger business-continuity strategy, says Bobby LeBlanc, senior director of business services at this Houston energy company. Dynegy considers crises management teams the front-line defenders against a range of potential business disruptions: an unruly virus or hack attack, certainly, but also fire, bomb threats, terrorists attacks and natural disasters. For a hurricane, he could pull together a team hours or days in advance, and, besides the network and data-center techies, he’ll also make sure the team includes a meteorologist. On the other hand, for a fast-spreading worm that hits with no warning, IT-related team members would meet quickly and handle containment on their own. “Flexibility is absolutely key. You have to be prepared for practically anything,” LeBlanc says.
As to what IT people to involve, start at the top. CIO and top network executive support is critical. They “need to support the team with resources,” particularly people, Lucas says. She warns that in a large company, many IRT functions easily can be full-time jobs.
Often the network manager is the IRT champion, calling for help after being overrun by intrusion-detection-system alarm investigations and other constant security-related incidents. When a company has a chief security officer, that person tends to lead the IRT – as all IT team members must be security-trained. Recognizing the symptoms of a security breach and determining what has been or could be compromised are core IRT responsibilities.
Even so, a team likely will draw heavily on network staff, and the network executive must be supportive. And all IT departments could be called upon. For instance, the data-center manager must be willing to supply staff to help with an investigation or to activate backup plans.
If your company has a zero-tolerance policy that says every potential threat must be planned for and every incident analyzed, then IRT work will be time-consuming, LeBlanc warn. IT-related IRT roles likely will be full time, especially for large companies.
Schlumberger’s Chiock says full-time incident response professionals are perfect for security prevention tasks. They should handle patch management, firewall administration, employee policy creation and training. As such, IRT members gain the kind of systems knowledge they need to do their response jobs.
As for training, CERT in July crafted a multi-year IRT certification program for IT-related initial incident handling all the way through team-management level, says Barbara Laswell, manager for the Network Systems Survivability program at CERT Coordination Center at Carnegie Mellon University.
Similarly, the Forum of Incident Response and Security Teams (FIRST) assists companies – about 200 worldwide since its founding 10 years ago – in creating formal, internal teams, Laswell says. CERT is a founding member of this international coalition of IRT specialists, which offers symposiums, written guidelines, technical information and access to experienced IRT professionals.
Despite the Sept. 11 attacks and the U.S.’s continued geopolitical turmoil, training on how to respond to incidents hasn’t changed, says Klaus-Peter Kossakowski, chair of the FIRST Steering Committee, in Hanover, Germany.
If you learn how to thwart a malcontent hacker, then you will know how to defend against Internet-borne terrorism. Lucas points to software providers Guidance Software and New Technologies, as good sources for computer security forensics training.
The IRT champion also must consider how to give employees guidance on how to report suspicious activity or what to do when their desktops are threatened be it by virus or a bomb threat. Telephone hotlines and e-mail addresses are helpful as reporting tools, while e-mail broadcasts let the team communicate to employees about incidents. Software vendors such as Remedy also offer so-called crisis-management products. These help automate the steps involved in incident response from receiving the first alert through closure.
Similarly, IT outsourcers such as Schlumberger’s Sema use security assessment tools helpful for an IRT. The “security dashboard,” developed for Schlumberger’s internal use, gauges the health of security across a company rather than relying on multiple logs, Chiock says.
The dashboard tracks incident and response statistics, found vulnerabilities and training completed, for instance, and generates reports. These reports help tally performance pay – 5% of total compensation for every manager is tied to meeting security goals, he says. Equally important, the dashboard lets Chiock update the board of directors on security issues, keeping the purse strings open.
In today’s networked world, incidents are a given. Only by proactively managing them with dedicated resources will they cease to hold business-threatening power.




