When something happens · 4.3
Being able to answer afterwards
Being able to answer afterwards. What it costs, who decides, and what usually goes wrong.
Where workforce visibility is separately justified and disclosed, the reference describes a related monitoring use case; it should not be treated as proof of intent.
For an independent reference point, see CISA incident response resources.
The question
Can you answer what happened, three weeks later
Forensic readiness is not an incident response capability. It is the set of things that must already be true for anybody to reconstruct events afterwards, and almost all of it is decided long before anything happens.
The test is simple. If a machine were compromised on a Tuesday and you learned about it the following month, could you establish which files were touched, by which account, and where they went?
Logs
Four properties, and most environments miss two
They exist. Many machine controllers log nothing usable, which is why governance at the point of transfer matters more here than logging at the endpoint.
They are retained. Default retention is frequently days. An incident discovered a month later needs a month of history, and the standard has expectations about retention.
They are somewhere else. Logs held only on the affected system are the first thing an intruder alters and the first thing a reimage destroys.
The clocks agree. Time synchronisation across systems sounds like housekeeping and is the difference between a sequence of events and a pile of records that cannot be ordered. Reconstructing an incident across systems whose clocks differ by minutes is substantially harder and sometimes impossible.
Imaging
Being able to take a copy without destroying the original
Preservation is a contractual obligation and it is also the practical prerequisite for finding out anything. Somebody needs to know how to take an image of an affected system, and needs to know before the morning it is required.
For most manufacturers the honest answer is that this capability is bought rather than built, which is fine provided the arrangement exists in advance.
Who does the analysis
Not you
Digital forensics is a specialism and an incident is a poor time to learn it. What a supplier needs is a relationship arranged beforehand: a firm, a contact, an agreed rate and an understanding of what they would need from you.
Retainers exist and are not expensive relative to the cost of spending the first two days finding somebody. Your insurer may also require a firm from their panel, which is worth knowing before you call your own.
The floor
Where the evidence is thinnest
Machine controllers are the part of the environment least likely to record anything and most likely to be reimaged by a maintenance engineer trying to be helpful.
Two things help: a record kept at the point files are authorised and transferred, which exists independently of the machine, and an instruction to maintenance staff that a suspected compromise is not to be resolved by reimaging.
The tabletop
Two hours, once a year
A scenario, the people who would actually be involved, and a facilitator asking what happens next. No systems, no technology, a whiteboard.
What it finds is consistent: the contact list is out of date, nobody knows who decides, the certificate has expired, and two people believed somebody else was responsible for the same thing.
It also produces a record of an exercise, which the standard's incident response requirements expect to exist.
The paper copy
Because the network may be the problem
A printed plan with the contacts, the decision tree and the reporting requirements, held by the named person and their deputy.
This sounds old-fashioned until the day the file server is encrypted and the plan is on it.
Also
Elsewhere in when something happens
- What compliance actually costs, itemisedWhat compliance actually costs, itemised. What it costs, who decides, and what usually goes wrong.
- Reading a proposal that quotes a certificateReading a proposal that quotes a certificate. What it costs, who decides, and what usually goes wrong.
- What to build and what to buyWhat to build and what to buy. What it costs, who decides, and what usually goes wrong.
- Making the budget case to somebody who resents itMaking the budget case to somebody who resents it. What it costs, who decides, and what usually goes wrong.
- The costs that arrive after the purchase orderThe costs that arrive after the purchase order. What it costs, who decides, and what usually goes wrong.
- Doing this with almost no moneyDoing this with almost no money. What it costs, who decides, and what usually goes wrong.
- Who owns compliance, and why it cannot be nobodyWho owns compliance, and why it cannot be nobody. What it costs, who decides, and what usually goes wrong.
- Running it as a project rather than as a documentRunning it as a project rather than as a document. What it costs, who decides, and what usually goes wrong.
- Reporting to a board that wants one numberReporting to a board that wants one number. What it costs, who decides, and what usually goes wrong.
- When the date slips, which it willWhen the date slips, which it will. What it costs, who decides, and what usually goes wrong.
- Staying compliant after the assessmentStaying compliant after the assessment. What it costs, who decides, and what usually goes wrong.
- Working to two standards at onceWorking to two standards at once. What it costs, who decides, and what usually goes wrong.
- Training that changes what people doTraining that changes what people do. What it costs, who decides, and what usually goes wrong.
- How a control looks from the machineHow a control looks from the machine. What it costs, who decides, and what usually goes wrong.
- Contractors, temps and the visiting engineerContractors, temps and the visiting engineer. What it costs, who decides, and what usually goes wrong.
- Hiring for a role most suppliers have never filledHiring for a role most suppliers have never filled. What it costs, who decides, and what usually goes wrong.
- Giving people a way to say a control is unworkableGiving people a way to say a control is unworkable. What it costs, who decides, and what usually goes wrong.
- What staff are told about monitoringWhat staff are told about monitoring. What it costs, who decides, and what usually goes wrong.
- What counts as an incidentWhat counts as an incident. What it costs, who decides, and what usually goes wrong.
- Reporting obligations and their clocksReporting obligations and their clocks. What it costs, who decides, and what usually goes wrong.
- The first hour, and who decidesThe first hour, and who decides. What it costs, who decides, and what usually goes wrong.
- Telling a customer something happenedTelling a customer something happened. What it costs, who decides, and what usually goes wrong.
- What changes afterwards, and what shouldWhat changes afterwards, and what should. What it costs, who decides, and what usually goes wrong.
- The other frameworks you have also metThe other frameworks you have also met. What it costs, who decides, and what usually goes wrong.
- Export control, named and not advised onExport control, named and not advised on. What it costs, who decides, and what usually goes wrong.
- Your own suppliers, and what to ask themYour own suppliers, and what to ask them. What it costs, who decides, and what usually goes wrong.
- Suppliers outside the United StatesSuppliers outside the United States. What it costs, who decides, and what usually goes wrong.
- Where the data physically sitsWhere the data physically sits. What it costs, who decides, and what usually goes wrong.
- What is changing, and how to tellWhat is changing, and how to tell. What it costs, who decides, and what usually goes wrong.