Cybersecurity Guidelines for FSTI Providers
5.2. Detection and Analysis
The detection and analysis in incident response is a key step to identify and understand thoroughly cybersecurity event potentials, among others:
1.
Use a detection tool like Security Information and Event Management (SIEM) system to monitor activities to detect suspicious behavior or incident potentials. Things to pay attention to:
·
Integrate SIEM system with existing security tools and IT infrastructure (firewall, router, antivirus, etc.) to connect data to recognize anomalous patterns related to malicious activities. Ensure the SIEM system provides real-time analysis and visualization of security data, enabling rapid incident detection and alarm the security team through email, SMS, and other communication channels.
·
2.
Analyze system log and security alarm to detect indications of intrusion or unauthorized activities. Define scope and impact of the detected incident, including evaluating affected systems and estimating damage potentials resulting from it. Implement automatic response protocol for low-level threats, such as temporary blocking of suspicious Internet Protocol.
3.
4.
5.
Perform check and update regularly. Things to note:
·
Regular check to ensure that all security tools function correctly with the latest threat definition and patch.
·
Regular SIEM update.
56
Made with FlippingBook. PDF to flipbook with ease