<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="stratmliso.xsl"?>
<StrategicPlan xmlns="urn:ISO:std:iso:17469:tech:xsd:stratml_core" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="urn:ISO:std:iso:17469:tech:xsd:stratml_core http://xml.govwebs.net/stratml/references/StrategicPlanISOVersion20140401.xsd"><Name>CYBERTHREAT RECOGNITION &amp; MITIGATION: A GUIDE FOR SMALL &amp; MEDIUM SIZED BUSINESSES (SMBs)</Name><Description/><OtherInformation>This document is provided for educational and informational purposes only and is not intended and should not be construed as providing legal advice. U.S. Government and the IC Private Sector Public Sector Analyst exchange program partners (the “Exchange Program Partners”) do not warrant or assume any legal liability or responsibility for the accuracy,
completeness, or usefulness of any information, apparatus, product, or process discussed in this document. U.S. Government and the Exchange Program Partners do not endorse or recommend any commercial products, processes, or services. The views and opinions expressed in this document do not necessarily state or reflect those of the U.S. Government
or the Exchange Program Partners, and they may not be used for advertising or product endorsement purposes.</OtherInformation><StrategicPlanCore><Organization><Name>2016 PUBLIC-PRIVATE ANALYTIC EXCHANGE PROGRAM</Name><Acronym>PPAEP</Acronym><Identifier>_406db18c-bbd4-11e6-985b-d6d3f7e90587</Identifier><Description>This program enables intelligence community analysts and private sector partners to gain a greater understanding of how their disparate, yet complementary roles can work in tandem to ensure mission success.</Description><Stakeholder StakeholderTypeType="Generic_Group"><Name>SMBs</Name><Description>Small and medium-sized businesses.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Cyber Threat Recognition and Mitigation Group Contributors</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Department of Defense</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Defense Intelligence Agency</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Federal Bureau of Investigation</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Amgen</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Hewlett Packard Enterprise</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>StratusCyber Small Business Security</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Virginia Department of Taxation</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Armera Cyber Solutions</Name><Description/></Stakeholder></Organization><Vision><Description>Improved cybersecurity</Description><Identifier>_406db2ea-bbd4-11e6-985b-d6d3f7e90587</Identifier></Vision><Mission><Description>To provide a path to improved cybersecurity</Description><Identifier>_406db380-bbd4-11e6-985b-d6d3f7e90587</Identifier></Mission><Value><Name/><Description/></Value><Goal><Name>Preparation</Name><Description>Prepare for cyber-attack.</Description><Identifier>_406db402-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>Small businesses must prepare for cyber-attack. The first three steps to prepare for a cyber-attack on your business involve PEOPLE, SYSTEMS, and BACK-UPS.</OtherInformation><Objective><Name>People</Name><Description>Educate employees about the threat.</Description><Identifier>_406db48e-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>Step one, PEOPLE. Educate employees about the threat, starting with use of strong passwords and learning about threats like phishing.</OtherInformation></Objective><Objective><Name>Systems</Name><Description>Protect your systems and data.</Description><Identifier>_406db51a-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>Step two, SYSTEMS. Protect your systems and data by using some of the many software tools available, starting with Anti-Virus and a Firewall.</OtherInformation></Objective><Objective><Name>Back-Up</Name><Description>Back up your data.</Description><Identifier>_406db59c-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>BACK-UPS, step three, gives you a do-over, after an attack instead of going out of business, it allows you to start again from where you left off.</OtherInformation></Objective></Goal><Goal><Name>Prevention</Name><Description>Prevent cyber-security breaches.</Description><Identifier>_406db632-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>Some of the most affordable yet effective prevention
techniques that SMBs can employ to prevent cyber-security
breaches include: firewalls, intrusion prevention software
and Anti-Virus software, strong passwords with expiration
timers, disabling and uninstalling any unused services and
software to limit entry points into the system, application
whitelisting/black listing and physical access controls (e.g.
locked doors, offices, cabinets).
Software should also be patched with the latest vendor
releases so that known security flaws are closed.</OtherInformation><Objective><Name>Firewalls</Name><Description/><Identifier>_406db6b4-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Intrusion Prevention</Name><Description/><Identifier>_406db740-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Virus Protection</Name><Description/><Identifier>_406db7d6-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Password Protection</Name><Description/><Identifier>_406db862-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Entry Points</Name><Description/><Identifier>_406db8ee-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.5</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Whitelisting/Black Listing</Name><Description/><Identifier>_406db9c0-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.6</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Physical Access</Name><Description/><Identifier>_406dba60-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.7</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Software Patches</Name><Description/><Identifier>_406dbaf6-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>2.8</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Detection</Name><Description>Monitor the network for advanced persistent threats.</Description><Identifier>_406dbb8c-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>Consider using a managed security service provider to monitor your network for advanced persistent threats. An endpoint security solution will provide additional security for your endpoints (laptops/workstations/servers).  This defense-in-depth strategy enhances the security tools and best-practices in your prevention strategy. Your diligence is critical!</OtherInformation><Objective><Name>Signs &amp; Symptoms</Name><Description>Familiarize yourself with the signs and symptoms of an infected system.</Description><Identifier>_406dbc2c-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Emerging Threats &amp; Security Updates</Name><Description>Use security resources and information channels to keep current on emerging threats and security updates.</Description><Identifier>_406dbcc2-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Security Service Providers</Name><Description>Keep the contact information of security service providers that manage your security.</Description><Identifier>_406dbd6c-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>3.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Security Service Providers</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Other Professionals</Name><Description>Identify other professionals that you can call to help you recognize and respond to security incidents and breaches. </Description><Identifier>_406dbe0c-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>3.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Response</Name><Description>Respond thoroughly to incidents.</Description><Identifier>_406dbeac-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>When an incident is detected, it is important to respond thoroughly
and timely.</OtherInformation><Objective><Name>Contracts</Name><Description>Work with pre-established contacts to contain, mitigate, and eradicate the threat.</Description><Identifier>_406dbf56-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Alerting &amp; Reporting</Name><Description>Alert affected parties and provide progress reports throughout the incident.</Description><Identifier>_406dbff6-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Removal</Name><Description>Ensure all the attacker's artifacts are eliminated from affected systems.</Description><Identifier>_406dc0aa-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4.3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Causes &amp; Symptoms</Name><Description>Determine cause and symptoms of the incident.</Description><Identifier>_406dc186-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4.4</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Patches</Name><Description>Patch all vulnerabilities.</Description><Identifier>_406dc258-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4.5</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Restoration</Name><Description>Restore data appropriately from backups.</Description><Identifier>_406dcab4-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4.6</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Evidence</Name><Description>Preserve evidence so law enforcement action can potentially be taken against the perpetrator.</Description><Identifier>_406dcb18-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>4.7</SequenceIndicator><Stakeholder StakeholderTypeType="Person"><Name>Law Enforcement Officials</Name><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Recovery</Name><Description>Create a disaster recovery plan.</Description><Identifier>_406dcb19-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator>5</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Internet Service Providers</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Hardware Vendors</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Trade Associations</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Ready.gov</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>NIST</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>SBA</Name><Description/></Stakeholder><OtherInformation>You've been hacked, you've responded appropriately to the incident and now you need to recover. The extent of your recovery may include the computer room and environment, the hardware, connectivity to a Internet Service Provider (ISP), software applications, and restoration of your company's data.
Help from your ISP, hardware vendor, trade associations or major clients may be available. A number of helpful ideas can be found on the Ready.gov, NIST, SBA and other official websites. If you have not yet created one, a disaster contingency planning policy or reference book can be crucial in times of crisis.</OtherInformation><Objective><Name/><Description/><Identifier>_406dcb1a-bbd4-11e6-985b-d6d3f7e90587</Identifier><SequenceIndicator/><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><PublicationDate>2016-12-06</PublicationDate><Source>http://files.constantcontact.com/311cbc2c401/29358b0c-5a58-4ba1-8aa4-0716037493b5.pdf</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></StrategicPlan>