Assignment 3: Incident Response (IR) Strategic Decisions
Suppose that you have been alerted of a potential incident involving a suspected worm spreading via buffer overflow techniques, compromising Microsoft IIS Web servers. As the IR Team leader, it is your responsibility to determine the next steps.
Write a two to three (2-3) page paper in which you:
Explain in detail the initial steps that would need to be made by you and the IR team in order to respond to this potential incident.
Construct a process-flow diagram that illustrates the process of determining the incident containment strategy that would be used in this scenario, and identify which containment strategy would be appropriate in this case, through the use of graphical tools in Visio, or an open source alternative such as Dia. Note: The graphically depicted solution is not included in the required page length.
Construct a process flow diagram to illustrate the process(es) for determining if / when notification of the incident should be relayed to upper management, and explain how those communications should be structured and relayed through the use of graphical tools in Visio, or an open source alternative such as Dia. Note: The graphically depicted solution is not included in the required page length.
Detail the incident recovery processes for the resolution of this incident.
Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow APA or school-specific format. Check with your professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s name, the course title, and the date. The cover page and the reference page are not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Summarize the various types of disasters, response and recovery methods.
Develop techniques for different disaster scenarios.
Use technology and information resources to research issues in disaster recovery.
Write clearly and concisely about disaster recovery topics using proper writing mechanics and technical style conventions.
Points: 75
Assignment 3: Incident Response (IR) Strategic Decisions
Criteria
Unacceptable
Below 60% F
Meets Minimum Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Explain in detail the initial steps that would need to be made by you and the IR team in order to respond to this potential incident.
Weight: 15%
Did not submit or incompletely explained in detail the initial steps that would need to be made by you and the IR team in order to respond to this potential incident.
Insufficiently explained in detail the initial steps that would n.
1. Assignment 3: Incident Response (IR) Strategic Decisions
Suppose that you have been alerted of a potential incident
involving a suspected worm spreading via buffer overflow
techniques, compromising Microsoft IIS Web servers. As the IR
Team leader, it is your responsibility to determine the next
steps.
Write a two to three (2-3) page paper in which you:
Explain in detail the initial steps that would need to be made by
you and the IR team in order to respond to this potential
incident.
Construct a process-flow diagram that illustrates the process of
determining the incident containment strategy that would be
used in this scenario, and identify which containment strategy
would be appropriate in this case, through the use of graphical
tools in Visio, or an open source alternative such as Dia. Note:
The graphically depicted solution is not included in the required
page length.
Construct a process flow diagram to illustrate the process(es)
for determining if / when notification of the incident should be
relayed to upper management, and explain how those
communications should be structured and relayed through the
use of graphical tools in Visio, or an open source alternative
such as Dia. Note: The graphically depicted solution is not
included in the required page length.
Detail the incident recovery processes for the resolution of this
incident.
Use at least three (3) quality resources in this assignment. Note:
Wikipedia and similar Websites do not qualify as quality
resources.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size
12), with one-inch margins on all sides; citations and references
must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the
2. student’s name, the professor’s name, the course title, and the
date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this
assignment are:
Summarize the various types of disasters, response and recovery
methods.
Develop techniques for different disaster scenarios.
Use technology and information resources to research issues in
disaster recovery.
Write clearly and concisely about disaster recovery topics using
proper writing mechanics and technical style conventions.
Points: 75
Assignment 3: Incident Response (IR) Strategic Decisions
Criteria
Unacceptable
Below 60% F
Meets Minimum Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Explain in detail the initial steps that would need to be made
by you and the IR team in order to respond to this potential
incident.
Weight: 15%
Did not submit or incompletely explained in detail the initial
steps that would need to be made by you and the IR team in
order to respond to this potential incident.
3. Insufficiently explained in detail the initial steps that would
need to be made by you and the IR team in order to respond to
this potential incident.
Partially explained in detail the initial steps that would need to
be made by you and the IR team in order to respond to this
potential incident.
Satisfactorily explained in detail the initial steps that would
need to be made by you and the IR team in order to respond to
this potential incident.
Thoroughly explained in detail the initial steps that would need
to be made by you and the IR team in order to respond to this
potential incident.
2. Construct a process-flow diagram that illustrates the process
of determining the incident containment strategy that would be
used in this scenario, and identify which containment strategy
would be appropriate in this case, through the use of graphical
tools in Visio, or an open source alternative such as Dia.
Weight: 25%
Did not submit or incompletely constructed a process-flow
diagram that illustrates the process of determining the incident
containment strategy that would be used in this scenario, and
did not submit or incompletely identified which containment
strategy would be appropriate in this case, through the use of
graphical tools in Visio, or an open source alternative such as
Dia.
Insufficiently constructed a process-flow diagram that
illustrates the process of determining the incident containment
strategy that would be used in this scenario, and insufficiently
identified which containment strategy would be appropriate in
this case, through the use of graphical tools in Visio, or an open
source alternative such as Dia.
Partially constructed a process-flow diagram that illustrates the
process of determining the incident containment strategy that
would be used in this scenario, and partially identified which
containment strategy would be appropriate in this case, through
the use of graphical tools in Visio, or an open source alternative
4. such as Dia.
Satisfactorily constructed a process-flow diagram that
illustrates the process of determining the incident containment
strategy that would be used in this scenario, and satisfactorily
identified which containment strategy would be appropriate in
this case, through the use of graphical tools in Visio, or an open
source alternative such as Dia.
Thoroughly constructed a process-flow diagram that illustrates
the process of determining the incident containment strategy
that would be used in this scenario, and thoroughly identified
which containment strategy would be appropriate in this case,
through the use of graphical tools in Visio, or an open source
alternative such as Dia.
3. Construct a process flow diagram to illustrate the process(es)
for determining if / when notification of the incident should be
relayed to upper management, and explain how those
communications should be structured and relayed through the
use of graphical tools in Visio, or an open source alternative
such as Dia.
Weight: 25%
Did not submit or incompletely
constructed a process flow diagram to illustrate the process(es)
for determining if / when notification of the incident should be
relayed to upper management, and did not submit or
incompletely explained how those communications should be
structured and relayed through the use of graphical tools in
Visio, or an open source alternative such as Dia.
Insufficiently constructed a process flow diagram to illustrate
the process(es) for determining if / when notification of the
incident should be relayed to upper management, and
insufficiently explained how those communications should be
structured and relayed through the use of graphical tools in
Visio, or an open source alternative such as Dia.
Partially constructed a process flow diagram to illustrate the
process(es) for determining if / when notification of the incident
should be relayed to upper management, and partially explained
5. how those communications should be structured and relayed
through the use of graphical tools in Visio, or an open source
alternative such as Dia.
Satisfactorily constructed a process flow diagram to illustrate
the process(es) for determining if / when notification of the
incident should be relayed to upper management, and
satisfactorily explained how those communications should be
structured and relayed through the use of graphical tools in
Visio, or an open source alternative such as Dia.
Thoroughly constructed a process flow diagram to illustrate the
process(es) for determining if / when notification of the incident
should be relayed to upper management, and thoroughly
explained how those communications should be structured and
relayed through the use of graphical tools in Visio, or an open
source alternative such as Dia.
4. Detail the incident recovery processes for the resolution of
this incident.
Weight: 20%
Did not submit or incompletely detailed the incident recovery
processes for the resolution of this incident.
Insufficiently detailed the incident recovery processes for the
resolution of this incident.
Partially detailed the incident recovery processes for the
resolution of this incident.
Satisfactorily detailed the incident recovery processes for the
resolution of this incident.
Thoroughly detailed the incident recovery processes for the
resolution of this incident.
5. 3 references
Weight: 5%
No references provided
Does not meet the required number of references; all references
poor quality choices.
Does not meet the required number of references; some
references poor quality choices.
Meets number of required references; all references high quality
6. choices.
Exceeds number of required references; all references high
quality choices.
6. Clarity, writing mechanics, and formatting requirements
Weight: 10%
More than 8 errors present
7-8 errors present
5-6 errors present
3-4 errors present
0-2 errors present