Cloud Incident Response

Expand all | Collapse all

Deliverable 2: Cloud Incident Response Framework (Execution)

  • 1.  Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Jan 06, 2020 05:46:00 PM
    Dear team, 

    Thank you to all who volunteered to take up the chapters. Let's proceed with the execution. Please input the content for your respective sections in these 2 weeks and we'll do a review / discussion at the end of it. We still require volunteers for the Containment, Eradication and Recovery segments, let me know if there is anyone interested in taking this up! 

    From CSA's social media, it looks like our Quick Guide is gaining some traction, which helps in the dissemination of this deliverable. Great job to everyone who helped in the Quick Guide! Let's keep it up for this framework. 


    Link



    ------------------------------
    Jane Chow
    Dec 12, 2019 · Notified 48 people
    ------------------------------


  • 2.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Apr 28, 2020 01:51:00 AM
    Hi Everyone, 

    With the primer deliverable 'Cloud Incident Response - A Quick Guide' now released (https://cloudsecurityalliance.org/artifacts/cloud-incident-response-framework-a-quick-guide/) , I would like to urge the WG to push ahead with the development of the full Cloud Incident Response Framework paper.

    The draft can be found here: https://docs.google.com/document/d/1kOnQzlBJFUMFOZNkfKEEeqH8ctuLmXokVmrs3kcH7-U/edit?usp=sharing 

    Please go through the paper, and contribute contents in areas where it is lacking, or feedback / comments and suggested edits in areas where you think can be improved. We will be resolving these inputs as we go along. 

    Feel free to also sound out any thoughts for discussion here in this thread, and we can have our WG's Co-Chairs and members chip in.

    We will aim to stock-take on this current round of contributions by next Friday (8 May 2020).

    Thanks!

    ------------------------------
    Haojie Zhuang
    Research Director, APAC
    CSA
    Singapore
    ------------------------------



  • 3.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 08, 2020 09:48:00 AM
    Hello,

    Is this fill framework still being worked? I haven't heard or seen much activity on it as of late.

    Chris

    ------------------------------
    Christopher Hughes
    Cloud Security Engineer
    Resilient Consulting LLC
    ------------------------------



  • 4.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 08, 2020 10:37:00 AM
    Hi,

    I believe Sean Heide is now the analyst for this paper.

    ------------------------------
    Michael Roza CPA, CISA, CIA
    ------------------------------



  • 5.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 09, 2020 07:48:00 AM
    Hello All,

    I also wish to know how I can continue to work on this.

    Thx

    Ricci





  • 6.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 09, 2020 08:27:00 AM

    Hi Ricci,

    I think Sean Heide is the CSA analyst assigned to this paper.

    Best regards,






  • 7.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 09, 2020 08:57:00 AM
    Edited by Saan Vandendriessche Sep 09, 2020 08:57:48 AM
    Hi Michael,

    Thanks for the feedback. With that, do you mean we should reach out to Sean instead of Haojie or is there another WG?
    I verified the document linked above (https://docs.google.com/document/d/1kOnQzlBJFUMFOZNkfKEEeqH8ctuLmXokVmrs3kcH7-U/edit?usp=sharing) and there are still some blank pieces we could continue on.

    Would love to continue my support on this deliverable.

    Many thanks.

    Best regards,

    Saan

    ------------------------------
    Saan Vandendriessche CCSP | CISSP | CRISC
    Cyber Security Manager
    Deloitte
    Brussels
    ------------------------------



  • 8.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 09, 2020 10:10:00 AM

    Hi Saan,

    I'm making a deeper inquiry right now.

    Best regards,






  • 9.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 09, 2020 11:42:00 PM
    You can count me in too.
    regards

    ------------------------------
    Olivier Caleff - CSA French Chapter - Chapter Leader - [email protected] - https://CloudSecurityAlliance.fr
    ------------------------------



  • 10.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 10, 2020 08:06:00 AM
    Hi,

    I went through the document and identified as best I could recall, the sections titles (yellow highlighted) and materials (blue highlighted) that need work.

    I gave Saan, Ricci, and Olivier comment access until you chose which sections you want to complete.

    @Christopher Hughes, I need your email address to be able to add you.


    ------------------------------
    Michael Roza CPA, CISA, CIA
    ------------------------------



  • 11.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 10, 2020 08:16:00 AM
    [email protected]

    ------------------------------
    Christopher Hughes
    Cloud Security Engineer
    Resilient Consulting LLC
    ------------------------------



  • 12.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 10, 2020 08:46:00 AM
    Done

    ------------------------------
    Michael Roza CPA, CISA, CIA
    ------------------------------



  • 13.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 12, 2020 07:54:00 AM
    Hello Michael,

    When I glanced through the published Cloud Incident Response document and the one you let us edit differs quite a bit.

    Please advise how should we start the review and edit?

    Thx

    Ricci





  • 14.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 12, 2020 08:33:00 AM
    Edited by Michael Roza Sep 12, 2020 08:43:11 AM
    Hi Ricci,

    Yes, the first document was a short summary of what was to come.
    I have contacted CSA leadership and they have assigned CSA resources to this effort.

    @Sean Heide
    @Ekta Mishra

    Generally, yellow highlighted sections indicate a section that needs work. 
    Blue is a bit more specific and is explained in the document.​

    If you have chosen a section or sections to work on you could include a comment by the section title (s).
    If you are ready to commit then I could give you edit access immediately or you can wait for the CSA resources.

    ------------------------------
    Michael Roza CPA, CISA, CIA
    ------------------------------



  • 15.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 14, 2020 12:58:00 PM
    Thanks Michael!
    I've started to run through the document and adding some thoughts/comments.
    Will check on which sections I can commit to write/rework in the coming days (yellow/blue)

    ------------------------------
    Saan Vandendriessche CCSP | CISSP | CRISC
    Cyber Security Manager
    Deloitte
    Brussels
    ------------------------------



  • 16.  RE: Deliverable 2: Cloud Incident Response Framework (Execution)

    Posted Sep 14, 2020 01:25:00 PM
    Hi Saan,

    Fantastic!!!

    ------------------------------
    Michael Roza CPA, CISA, CIA
    ------------------------------