id: "IR-04(13)" title: "Behavior Analysis" family: "IR" family_name: "Incident Response" sort_id: "ir-04.13" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True
Statement
Analyze anomalous or suspected adversarial behavior in or related to {{ insert: param, ir-04.13_odp }}.
Guidance
If the organization maintains a deception environment, an analysis of behaviors in that environment, including resources targeted by the adversary and timing of the incident or event, can provide insight into adversarial tactics, techniques, and procedures. External to a deception environment, the analysis of anomalous adversarial behavior (e.g., changes in system performance or usage patterns) or suspected behavior (e.g., changes in searches for the location of specific resources) can give the organization such insight.
Assessment Objective
anomalous or suspected adversarial behavior in or related to {{ insert: param, ir-04.13_odp }} are analyzed.
Incident response policy
procedures addressing system monitoring tools and techniques
incident response plan
system monitoring logs or records
system monitoring tools and techniques documentation
system configuration settings and associated documentation
security plan
system component inventory
network diagram
system protocols documentation
list of acceptable thresholds for false positives and false negatives
system security plan
other relevant documents or records
Organizational personnel with information security responsibilities
system/network administrators
Organizational processes for detecting anomalous behavior