id: "IR-04(12)" title: "Malicious Code and Forensic Analysis" family: "IR" family_name: "Incident Response" sort_id: "ir-04.12" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True
Statement
Analyze malicious code and/or other residual artifacts remaining in the system after the incident.
Guidance
When conducted carefully in an isolated environment, analysis of malicious code and other residual artifacts of a security incident or breach can give the organization insight into adversary tactics, techniques, and procedures. It can also indicate the identity or some defining characteristics of the adversary. In addition, malicious code analysis can help the organization develop responses to future incidents.
Assessment Objective: malicious code remaining in the system is analyzed after the incident;
Assessment Objective: other residual artifacts remaining in the system (if any) are analyzed after the incident.
Incident response policy
procedures addressing incident handling
procedures addressing code and forensic analysis
procedures addressing incident response
incident response plan
system design documentation
malicious code protection mechanisms, tools, and techniques
results from malicious code analyses
system security plan
system audit records
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
organizational personnel with responsibility for malicious code protection
organizational personnel responsible for incident response/management
Organizational process for incident response
organizational processes for conducting forensic analysis
tools and techniques for analysis of malicious code characteristics and behavior