Melissa Krasnow | February 3, 2017
In December 2016, the National Institute of Standards and Technology (NIST) published a guide on cyber-security event recovery that provides information about developing a recovery plan in the form of a customized playbook before a cyber-event, as well as examples of recovery plans for a ransomware attack and data breach. This article sets forth items that can be included in a playbook.
While the NIST Guide for Cybersecurity Event Recovery applies to US federal agencies, it should be useful to any organization. The guide extends, but does not replace, existing federal guidelines regarding incident response. A cyber-incident response plan should be developed as part of a larger business continuity plan, which may include other plans and procedures for ensuring minimal impact to business functions (e.g., disaster recovery plans and crisis communication plans).
Recovery activities encompass a tactical recovery phase and a strategic recovery phase.
The tactical recovery phase will depend on performing the following actions before and during the cyber-event.
The strategic recovery phase will depend on performing the following actions before and during the cyber-event.
Appendix A to the guide includes the following checklist of steps that should be covered in the playbook for a particular cyber-event.
The organization understood the need to be prepared and conducted planning to operate in a diminished condition. The playbook includes the following critical elements.
The following steps summarize the activities of the recovery team in the tactical recovery phase.
The following steps summarize the activities performed during the strategic recovery phase.
Opinions expressed in Expert Commentary articles are those of the author and are not necessarily held by the author's employer or IRMI. Expert Commentary articles and other IRMI Online content do not purport to provide legal, accounting, or other professional advice or opinion. If such advice is needed, consult with your attorney, accountant, or other qualified adviser.