Preserving Forensic Data in a Cyber Incident Response Plan
Summary
Under the threat of increased attacks, in IT and in particular OT infrastructure, we are reviewing CISA’s targeted cyber intrusion and detection mitigation strategies. Our series looks at the ConsoleWorks answer to these strategies, from preserving forensic data in a cyber incident response plan, strict role-based access control, DNS logging, credential management and more. Let’s look at CISA’s recommended strategies and how ConsoleWorks simplifies forensic data retention as part of your cyber incident response plan. More important than not running antivirus software that could change critical dates after the fact and reduce the quality of your forensic data, you also need to know what the state of the device looked like prior to the attack. For more on increasing your defense capabilities, you can see our recent paper on achieving cybersecurity maturity and going beyond Zero Trust security, including technology and design considerations, here.