id: "IR-04(12)" title: "Malicious Code and Forensic Analysis" family: "IR" family_name: "Incident Response" sort_id: "ir-04.12" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True


Statement

Analyze malicious code and/or other residual artifacts remaining in the system after the incident.

Guidance

When conducted carefully in an isolated environment, analysis of malicious code and other residual artifacts of a security incident or breach can give the organization insight into adversary tactics, techniques, and procedures. It can also indicate the identity or some defining characteristics of the adversary. In addition, malicious code analysis can help the organization develop responses to future incidents.

Assessment Objective: malicious code remaining in the system is analyzed after the incident;

Assessment Objective: other residual artifacts remaining in the system (if any) are analyzed after the incident.

Incident response policy

procedures addressing incident handling

procedures addressing code and forensic analysis

procedures addressing incident response

incident response plan

system design documentation

malicious code protection mechanisms, tools, and techniques

results from malicious code analyses

system security plan

system audit records

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel with responsibility for malicious code protection

organizational personnel responsible for incident response/management

Organizational process for incident response

organizational processes for conducting forensic analysis

tools and techniques for analysis of malicious code characteristics and behavior