008-6-Cyber Security: Incident Reporting and Response Planning

In the Reports Portal, select Repository > Standard Content > NERC> CIP-008 Incident Reporting and Response Planning.

NERC Standard 008-6: Incident Reporting and Response Planning creates and maintains an appropriate incident response plan for your BES cyber system, ensuring that your organization supports and maintains appropriate cyber security requirements for your organization.

Dashboards Reports

Attack and Suspicious Activity Overview

Command and Control Overview

Lateral Movement Overview

Privilege Escalation Overview

MITRE ATT&CK ICS Overview

n/a

Attacks and Suspicious Activity Overview

Displays an overall view of the attackers, it's techniques and targets.

Charts:

  • Attack/Target Matrix

  • SSH Attacks- drilldown to SSH Attacks Overview Dashboard

  • Suspicious Activity Relationship

  • Top 5 Ports

  • Events Table

  • Web Attacks- drilldown to Web Attacks Overview Dashboard

Filters:

  • Agent Severity

  • Attack Technique

Command and Control Overview

Displays command and control events. You can drill down to this dashboard from the Insights dashboard.

Charts:

  • Command and Control Activity Flow

  • Events Table

Lateral Movement Overview

Displays lateral movement events which represent the way an attack spreads from an entry point to the rest of the network. For example, by placing malware on a user's computer, a malicious user could attempt to move laterally to infect other computers on the network, to infect internal servers, and so on until they reach their final target. The Lateral Movement Overview dashboard is interactive, so clicking on a specific item on a chart will render the other charts accordingly.

Charts:

  • Activity over Time

  • Source-Target IP Relationship

  • Events Table

MITRE ATT&CK ICS Overview

Displays an overview of MITRE ATT&CK events including charts that sort events by MITRE ATT&CK technique, tactic, and frequency.

Tactics, Alerts by MITRE ATT&CK Techniques, and Alert Distribution by MITRE ATT&CK Tactics are interactive charts, meaning they update and change as you interact with other charts in the dashboard.

Note: This dashboard requires ArcSight ESM to populate.

Charts:

  • Tactics

  • Alerts by MITRE ATT&CK Techniques

  • Alert Distribution by MITRE ATT&CK Tactics

  • Events Table

Privilege Escalation Overview

Displays privilege escalation events. This is a drill-down dashboard that can be reached from the NERC Insights dashboard.

Charts:

  • Privileged Groups
  • Events Table