The FDIC’s Incident Detection and Response Program
Report Information
Unimplemented Recommendations
Update the FDIC’s content development process based on emulated tests that did not generate notable events to identify where gaps in coverage exist within incident detection strategies.
Review current access permissions on FDIC endpoints and update permissions accordingly to prevent unauthorized users from disabling or interfering with endpoint detection and response services.
Update applicable FDIC directives and procedural documents, to ensure that the Division of Information Technology is notified of involuntary separations at, or prior to, the time of notification to the employee, and coordinate with appropriate stakeholders to establish risk-driven timetables for revoking and disabling access.
Update the current incident response testing procedures to ensure that the testing covers all National Institute of Standards and Technology Cybersecurity Framework incident response functions, and that updates based on the results of incident response testing are applied to the Incident Response Plan and/or other organizational plans, to include the Cybersecurity Event Recovery Plan.