id: "IR-04(13)" title: "Behavior Analysis" family: "IR" family_name: "Incident Response" sort_id: "ir-04.13" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True


Statement

Analyze anomalous or suspected adversarial behavior in or related to {{ insert: param, ir-04.13_odp }}.

Guidance

If the organization maintains a deception environment, an analysis of behaviors in that environment, including resources targeted by the adversary and timing of the incident or event, can provide insight into adversarial tactics, techniques, and procedures. External to a deception environment, the analysis of anomalous adversarial behavior (e.g., changes in system performance or usage patterns) or suspected behavior (e.g., changes in searches for the location of specific resources) can give the organization such insight.

Assessment Objective

anomalous or suspected adversarial behavior in or related to {{ insert: param, ir-04.13_odp }} are analyzed.

Incident response policy

procedures addressing system monitoring tools and techniques

incident response plan

system monitoring logs or records

system monitoring tools and techniques documentation

system configuration settings and associated documentation

security plan

system component inventory

network diagram

system protocols documentation

list of acceptable thresholds for false positives and false negatives

system security plan

other relevant documents or records

Organizational personnel with information security responsibilities

system/network administrators

Organizational processes for detecting anomalous behavior