Policies and Procedures: Security Incident Protocol

Prev Next

Ripple Treasury has developed a comprehensive Security Incident Protocol.  A formal assessment shall be undertaken immediately to determine the existence of an incident and whether the Security Incident Protocol should be implemented.  The Security & Compliance team will be the owner of the Security Incident Protocol. 

The Security Incident Protocol covers all essential and critical infrastructure elements, systems and networks, in accordance with key business activities. The protocol will incorporate appropriate elements of the Disaster Recovery and Business Continuity Plans when applicable as well as the resolution of Severity Level 1 and 2 issues.

The Security Incident Protocol will be periodically tested to ensure that it can be implemented in emergency situations and that all employees understand how it is to be executed. If Ripple Treasury experiences a Security Incident during the year, the protocol may not be formally tested at the discretion of the Security & Compliance Team.

All staff are made aware of the Security Incident Protocol and their respective roles. The Security Incident Protocol is updated periodically to consider changing circumstances.

Per Ripple Treasury’s MSA, a Security Incident is defined as an actual or Suspected unauthorized acquisition of Customer Data that compromises the security, confidentiality, or integrity of Personal Information maintained by Provider (Ripple Treasury) for Customer.  “Suspected” shall mean that the Provider’s IT Systems have reported a compromise or have behaved in such a manner as would lead a careful and knowledgeable IT professional to investigate the cause for such behavior.     

The Security Incident Response Team members include the Security & Compliance team and IT.  Other members, such as Internal Legal Counsel, Account Management, and Client Services may be included on an as needed basis or to perform certain critical tasks.

Awareness

Employees must be aware of their responsibilities in detecting security incidents to facilitate the incident response plan and procedures. All employees have the responsibility to assist in the incident response procedures within their areas of responsibility. Incident commanders are in place to spearhead the resolution of Severity Level 1 and 2 issues.  Ripple Treasury has retained Alert Logic to monitor servers on a 24x7x365 basis.  This monitoring process is to identify intrusions or any other suspicious activity.  If Alert Logic discovers any suspicious activity, Ripple Treasury is notified and the team will assess the situation and act in accordance with the Security Incident Protocol. 

All employees, regardless of job responsibilities, should be aware of the potential incident identifiers and who to notify in these situations. It is crucial to identify the incident and determine whether the deviation from normal operations within Ripple Treasury truly is an incident, and the extent of its impact on the flow of daily business. Information should be gathered from various sources such as log files, error messages, intrusion detection systems, firewalls, and other resources that may produce evidence to determine whether an event is an incident. If an event is determined to be an incident, it should be reported as soon as possible in order to allow the team enough time to collect evidence and take appropriate action.

Communication and Appropriate Action

There are two types of communications that are necessary during an incident:

  • Internal communication between management, members of the response team, and employees.

  • External communications related to customers, law enforcement personnel, and legal counsel.

Communication is essential and each member of the response team will have a contact list and instructions related to when and whom to contact.  Communication may be the initial contact of the proper local authorities (police/fire, etc.), technology support such as IT and/or partners (such as SWIFT).  It is important to define when it is or is not appropriate to include law enforcement or the media during an incident, due to the consequences that could either positively or negatively affect the organization.  If there is reasonable suspicion that a crime has been committed, law enforcement agencies should be contacted.  The decision to contact law enforcement will be made by the CEO or, in their absence, the senior most member of the response team.  Any report to law enforcement agencies should be accompanied by a strong request for confidentiality due to the sensitive nature of the Ripple Treasury client relationship.

Internal Communication

The response team is responsible for disseminating information to Ripple Treasury employees as appropriate.  Information will be shared with employees on a need to know basis, depending on the severity of the incident and potential impact to employees.  Information will be shared based upon job role.  It is the responsibility of each senior manager to communicate with their respective team member(s) if/when an incident arises.  The response team will discuss the internal communication plan.  If applicable, the most senior manager on the response team may provide information to the entire Ripple Treasury organization.  Information to the individual departments will be provided by the most senior leader of the team. 

Employees will be informed as promptly as possible, once an incident is identified as warranting employee notification. 

There may be incidents that do not require notification to the full Ripple Treasury team.  The Security & Compliance team may open a Severity Level 1 or 2 ticket at their discretion which will follow the standard internal incident management process. 

External Communication

If a customer’s confidential information may have been compromised, they should be contacted as soon as the severity of the incident is determined – not to exceed 72 hours from the discovery of the incident.  Ripple Treasury’s legal counsel may be contacted if the incident is determined to be valid. Legal counsel, along with the incident team and management, will determine the appropriate course of action.   All other clients will be communicated with on a need to know basis, at the discretion of the CEO or senior management. 

If the incident involves a Ripple Treasury customer who requires Payment Card Industry Compliance (PCI), management and the response team will follow the protocol outlined in PCI DSS Incident Handling.  Details of these procedures can be found in the SANS Security Institute White Paper PCI DSS and Incident Handling.

If the incident involves a regulatory disclosure, Ripple Treasury will notify the appropriate authority within the designated time frame subject to client contractual restrictions. 

External Communication

If a customer’s confidential information may have been compromised, they should be contacted as soon as the severity of the incident is determined – not to exceed 72 hours from the discovery of the incident. Ripple Treasury’s legal counsel may be contacted if the incident is determined to be valid. Legal counsel, along with the incident team and management, will determine the appropriate course of action. All other clients will be communicated with on a need to know basis, at the discretion of the CEO or senior management.

If the incident involves a Ripple Treasury customer who requires Payment Card Industry Compliance (PCI), management and the response team will follow the protocol outlined in PCI DSSIncident Handling. Details of these procedures can be found in the SANS Security Institute White Paper PCI DSS and Incident Handling.

If the incident involves a Ripple Treasury customer who requires Payment Card Industry Compliance (PCI), management and the response team will follow the protocol outlined in PCI DSSIncident Handling. Details of these procedures can be found in the SANS Security Institute White Paper PCI DSS and Incident Handling.

Documentation

Documenting the incident is essential in order to establish a written record of the situation.  This written documentation may be needed for insurance, law enforcement, internal re-evaluation, and customer relations purposes.  Documentation should include as much detail a possible to answer the questions: Who, What, When, Where, and Why.

Training

At the first indication of an incident, the team will meet (either in person or by phone) and begin the incident evaluation and response process.  All employees are required to read the Security Incident Protocol in order to understand the process and know their responsibilities in case there is an actual incident.  There will be a Security Incident Protocol test at least once every 12 months (unless the Security & Compliance team deem unnecessary due to a real incident during the year). 

Identification

It is crucial to identify the incident with the detection and determination of whether a deviation from normal operations within Ripple Treasury is truly an incident and its impact assuming that the deviation is indeed an incident.  Information should be gathered from various sources such as log files, error messages, intrusion detection systems, firewalls, and other resources that may produce evidence to determine whether an event is an incident. If an event is determined to be an incident, it should be reported as soon as possible in order to allow the team enough time to collect evidence and take appropriate action. Team members should be notified, and communication should be coordinated between the team along with designated staff (e.g. management and/or system administrators). Communication and coordination between members of the team is critical, especially if the scope of the incident can have a significant impact on business operations.

Incident responders should be documenting everything that they are doing and should be able to answer the Who, What, Where, Why, and How questions in case the documentation is to be used to prosecute the perpetrator(s) in court.  After determining the scope of the event and documenting the evidence, the team can move forward with the containment phase. 

Containment

The primary purpose of containment is to limit the damage and prevent any further damage from happening. There are several steps to this phase; however, each one is necessary in order to completely mitigate the incident and prevent the destruction of any evidence that may be needed later for prosecution or insurance purposes.

  • Short-term Containment: Prevent the issue from getting worse (which may include taking a server off-line if necessary)

  • System Back-Up: Attempt to capture any data about the issue before removing information

  • Long-term containment: Determine a long-term plan for resolution, impact and determine any clean up necessary

Eradication

This phase deals with the actual removal and restoration of affected systems.  As with each of the prior phases of incident response, continued documentation of all actions taken will be necessary to determine the overall impact to the organization.  It is necessary to ensure that proper steps were taken to remove malicious and other illicit content from the affected systems and ensure that they are thoroughly clean.  In general, that means a complete reimaging of a system’s hard drive(s) to ensure that any malicious content was removed to prevent reinfection.

This phase is also the point where defenses should be improved after learning what caused the incident and ensure that the system cannot be compromised again (e.g. installing patches to fix vulnerabilities that were exploited by the attacker, etc.).

Recovery

The purpose of this phase is to bring affected systems back into use carefully to ensure that it will not lead to another incident. It is essential to test, monitor, and validate the systems that are being put back into use to verify that they are not being re-infected by malware or compromised by some other means.

Lessons Learned/Root Cause Analysis

The purpose of this phase is to complete any documentation that was not done during the incident, as well as any additional documentation that may be beneficial in future incidents. The document should be written in a form of a report to provide a review of the entire incident.  The report should be able to answer the questions Who, What, Where, Why, and How that will be an important element of a lessons learned meeting to be held with members of the team, team members who helped in the resolution of the situation, and any other affected Ripple Treasury personnel. The overall goal is to learn from the incident that occurred within Ripple Treasury to improve the company’s performance and provide reference materials in the event there are future incidents. The documentation can also be used as training materials for new team members or as a benchmark to be used in comparison in future crises.  The lessons learned meeting should be performed as soon as possible after closure of the incident.  The summary should include:

  • When was the problem first detected and by whom?

  • What was the scope of the incident?

  • How was the incident contained and eradicated?

  • What work was performed during recovery?

  • In what areas was the team effective?

  • What areas need improvement?