Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.5
Related:
Clause 8
|
Incident Response and Recovery
|
Packet Capture Analysis (PCAP)
|
8.3 IDS
|
2-1 SPE 7
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management
Forensics and analysis tools (FAT) capture and reconstruct incidents: what happened, which systems were touched, and in what order. Packet capture is a technique (see PCAP), not a separate 3-1 heading.
Inability to learn from an incident or to support investigation. FAT does not prevent the incident.
Deploy in tandem with IDS. The threat picture used to tune IDS is a subset of what FAT must be able to reconstruct. Capture points, retention and reduction must be designed, not improvised after the breach.
The hard decisions are trade-offs: how much data, from where, how long it persists, and how it is reduced so analysts can use it. Capture that saturates a control link causes a new incident.
Plan FAT with a threat assessment. Volatile historian and alarm data may overwrite quickly; OT forensics is not a copy of enterprise disk imaging alone.