Objectives and Scope
The objectives of this IRP are to ensure:
- Immediate identification and management of security incidents.
- Compliance with Amazon-specific security requirements.
- Protection of sensitive information through robust access controls and timely reporting.
This IRP applies to:
- Quicksales system
- WebCRM for staff and employees
- PriceReporter.com website
- Terminal server for employees
- MS365 system, including corporate email, web storage, and Teams
- Backup servers and server monitoring systems
Daily backups are conducted, with SQL databases backed up hourly. Access to these systems requires encryption keys.
Description of Incidents
Common incident types include:
- Phishing and Malware Attacks
- Denial of Service (DoS) Attacks
- Ransomware and Social Engineering Attacks
- Data Loss (e.g., PII, intellectual property, financial information)
Incident Severity Criteria
Incident severity is determined by:
- Impact on operations
- Scope and cause of the incident
- Severity and nature of affected data
Reporting Procedures
Upon identifying an incident, the reporting individual (e.g., Customer Service, IT, or Vendor) must notify:
- Incident Response Manager
- COO
- Head of Developers
The Incident Response Manager will assess the severity and initiate the response process. For major incidents, the CEO will be informed and handle strategic decisions.
Notification Requirements – Amazon Notification: For incidents involving Amazon data, we will notify Amazon (via 3p-security@amazon.com) within 24 hours.
Enhanced Access Control Measures
Following Amazon’s review, Price Reporter Inc. has implemented the following access control measures:
- User Access Recertification: Access (both physical and logical) is recertified within 24 hours following internal role changes to ensure proper authorization.
- Physical Access Logging and Review: Logs of physical access, including failed attempts, are maintained and reviewed weekly to monitor for unauthorized access.
- Session Timeout Enforcement:
o Interactive Sessions: Timeout enforced after 15 minutes of inactivity, requiring re-authentication to resume.
o Non-Interactive Sessions: Timeout set to 24 hours, with re-authentication required to initiate new sessions. Non-sensitive data may have a longer timeout, as applicable. - MFA for Privileged Access: Multi-factor authentication (MFA) is enforced for all privileged accounts within the internal network, with logging and monitoring of access attempts.
Incident Response Team Roles
- CEO: Oversees strategic management and resources for significant incidents.
- COO: Manages communication with stakeholders and internal coordination.
- Incident Response Manager: Leads technical response and security oversight.
- Head of Developers: Manages application security, development, and disaster recovery.
The Incident Response Team (IRT) includes members with diverse technical and leadership skills to effectively manage security incidents.
Stages of Incident Response
- Identification: Detect and verify incidents using system monitoring and alerts.
- Containment: Isolate affected systems to prevent further damage.
- Investigation: Determine the incident’s cause and collect evidence.
- Eradication: Eliminate the root cause and restore affected systems.
- Recovery: Return to normal operations and monitor for recurrence.
- Lessons Learned: Conduct post-incident analysis to improve response.
System Restoration Procedures
- Data Restoration: Recover lost data from backups.
- System Rebuild: Rebuild damaged systems as necessary.
- Testing: Verify that restored systems are functioning correctly.
Customer Notification
- Notify affected customers immediately upon identifying an incident.
- Provide regular updates and offer support to impacted customers until the issue is resolved.
Testing and Training
- Testing: Annual tests, including tabletop exercises, simulated attacks, and penetration testing.
- Training: Quarterly training, including workshops and online modules.
- Evaluation: Regular reviews and assessments ensure continuous improvement of the IRP.
Contact List
Management
CEO: Igor London, 1 (201) 567-6646, iLondon@PriceReporter.com
COO: Sergey Bogol, 1 (201) 793-8338, SergeyB@PriceReporter.com
Technical Support
Lead IT Architect: Felix Gershcovich, FelixG@PriceReporter.com
Lead IT Admin: Ilia Lomadze, iLiaL@PriceReporter.com
Service Providers
Hosting: WhiteLabel, +1 (201) 425-4060, support@whitelabelitsolutions.com
Cloud Services: Microsoft Azure, +1 (800) 867-1389
NAS Storage and Backup: Synology Support: +1 (425) 296-3177
Retrospective and Continuous Improvement
After resolution, the IRP is reviewed to identify improvements, ensuring readiness for future incidents. This document is updated as needed to reflect best practices and evolving security requirements.
