<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<?xml-stylesheet type="text/xsl" href="../part2stratml.xsl"?><StrategicPlan><Name>CYBERTHREAT RECOGNITION &amp; MITIGATION: A GUIDE FOR SMALL &amp; MEDIUM SIZED BUSINESSES (SMBs)</Name><Description/><OtherInformation>This document is provided for educational and informational purposes only and is not intended and should not be construed as providing legal advice. U.S. Government and the IC Private Sector Public Sector Analyst exchange program partners (the “Exchange Program Partners”) do not warrant or assume any legal liability or responsibility for the accuracy,completeness, or usefulness of any information, apparatus, product, or process discussed in this document. U.S. Government and the Exchange Program Partners do not endorse or recommend any commercial products, processes, or services. The views and opinions expressed in this document do not necessarily state or reflect those of the U.S. Governmentor the Exchange Program Partners, and they may not be used for advertising or product endorsement purposes.</OtherInformation><StrategicPlanCore><Organization><Name>2016 PUBLIC-PRIVATE ANALYTIC EXCHANGE PROGRAM</Name><Acronym>PPAEP</Acronym><Identifier>_58c5ee48-bbd4-11e6-8232-8cd8f7e90587</Identifier><Description>This program enables intelligence community analysts and private sector partners to gain a greater understanding of how their disparate, yet complementary roles can work in tandem to ensure mission success.</Description><Stakeholder StakeholderTypeType="Generic_Group"><Name>SMBs</Name><Description>Small and medium-sized businesses.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Cyber Threat Recognition and Mitigation Group Contributors</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Department of Defense</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Defense Intelligence Agency</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Federal Bureau of Investigation</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Amgen</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Hewlett Packard Enterprise</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>StratusCyber Small Business Security</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Virginia Department of Taxation</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Armera Cyber Solutions</Name><Description/></Stakeholder></Organization><Vision><Description>Improved cybersecurity</Description><Identifier>_58c5ef24-bbd4-11e6-8232-8cd8f7e90587</Identifier></Vision><Mission><Description>To provide a path to improved cybersecurity</Description><Identifier>_58c5f096-bbd4-11e6-8232-8cd8f7e90587</Identifier></Mission><Value><Name/><Description/></Value><Goal><Name>Preparation</Name><Description>Prepare for cyber-attack.</Description><Identifier>_58c5f1ae-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Small businesses must prepare for cyber-attack. The first three steps to prepare for a cyber-attack on your business involve PEOPLE, SYSTEMS, and BACK-UPS.</OtherInformation><Objective><Name>People</Name><Description>Educate employees about the threat.</Description><Identifier>_58c5f244-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Step one, PEOPLE. Educate employees about the threat, starting with use of strong passwords and learning about threats like phishing.</OtherInformation></Objective><Objective><Name>Systems</Name><Description>Protect your systems and data.</Description><Identifier>_58c5f2d0-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Step two, SYSTEMS. Protect your systems and data by using some of the many software tools available, starting with Anti-Virus and a Firewall.</OtherInformation></Objective><Objective><Name>Back-Up</Name><Description>Back up your data.</Description><Identifier>_58c5f366-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>BACK-UPS, step three, gives you a do-over, after an attack instead of going out of business, it allows you to start again from where you left off.</OtherInformation></Objective></Goal><Goal><Name>Prevention</Name><Description>Prevent cyber-security breaches.</Description><Identifier>_58c5f3f2-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Some of the most affordable yet effective preventiontechniques that SMBs can employ to prevent cyber-securitybreaches include: firewalls, intrusion prevention softwareand Anti-Virus software, strong passwords with expirationtimers, disabling and uninstalling any unused services andsoftware to limit entry points into the system, applicationwhitelisting/black listing and physical access controls (e.g.locked doors, offices, cabinets).Software should also be patched with the latest vendorreleases so that known security flaws are closed.</OtherInformation><Objective><Name>Firewalls</Name><Description/><Identifier>_58c5f488-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Intrusion Prevention</Name><Description/><Identifier>_58c5f51e-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Virus Protection</Name><Description/><Identifier>_58c5f5b4-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Password Protection</Name><Description/><Identifier>_58c5f64a-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Entry Points</Name><Description/><Identifier>_58c5f6e0-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Whitelisting/Black Listing</Name><Description/><Identifier>_58c5f780-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Physical Access</Name><Description/><Identifier>_58c5f816-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Software Patches</Name><Description/><Identifier>_58c5f8b6-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>2.8</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Detection</Name><Description>Monitor the network for advanced persistent threats.</Description><Identifier>_58c5f956-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Consider using a managed security service provider to monitor your network for advanced persistent threats. An endpoint security solution will provide additional security for your endpoints (laptops/workstations/servers).  This defense-in-depth strategy enhances the security tools and best-practices in your prevention strategy. Your diligence is critical!</OtherInformation><Objective><Name>Signs &amp; Symptoms</Name><Description>Familiarize yourself with the signs and symptoms of an infected system.</Description><Identifier>_58c5f9ec-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Emerging Threats &amp; Security Updates</Name><Description>Use security resources and information channels to keep current on emerging threats and security updates.</Description><Identifier>_58c5fa96-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Security Service Providers</Name><Description>Keep the contact information of security service providers that manage your security.</Description><Identifier>_58c5fb36-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>3.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Security Service Providers</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Other Professionals</Name><Description>Identify other professionals that you can call to help you recognize and respond to security incidents and breaches. </Description><Identifier>_58c5fbd6-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>3.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Response</Name><Description>Respond thoroughly to incidents.</Description><Identifier>_58c5fcb2-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>When an incident is detected, it is important to respond thoroughlyand timely.</OtherInformation><Objective><Name>Contracts</Name><Description>Work with pre-established contacts to contain, mitigate, and eradicate the threat.</Description><Identifier>_58c5fd5c-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Alerting &amp; Reporting</Name><Description>Alert affected parties and provide progress reports throughout the incident.</Description><Identifier>_58c5fe06-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Removal</Name><Description>Ensure all the attacker's artifacts are eliminated from affected systems.</Description><Identifier>_58c5feba-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Causes &amp; Symptoms</Name><Description>Determine cause and symptoms of the incident.</Description><Identifier>_58c5ff64-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Patches</Name><Description>Patch all vulnerabilities.</Description><Identifier>_58c6000e-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Restoration</Name><Description>Restore data appropriately from backups.</Description><Identifier>_58c600cc-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Evidence</Name><Description>Preserve evidence so law enforcement action can potentially be taken against the perpetrator.</Description><Identifier>_58c60176-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>4.7</SequenceIndicator><Stakeholder StakeholderTypeType="Person"><Name>Law Enforcement Officials</Name><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Recovery</Name><Description>Create a disaster recovery plan.</Description><Identifier>_58c60270-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator>5</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Internet Service Providers</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Hardware Vendors</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Trade Associations</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Ready.gov</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>NIST</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>SBA</Name><Description/></Stakeholder><OtherInformation>You've been hacked, you've responded appropriately to the incident and now you need to recover. The extent of your recovery may include the computer room and environment, the hardware, connectivity to a Internet Service Provider (ISP), software applications, and restoration of your company's data.Help from your ISP, hardware vendor, trade associations or major clients may be available. A number of helpful ideas can be found on the Ready.gov, NIST, SBA and other official websites. If you have not yet created one, a disaster contingency planning policy or reference book can be crucial in times of crisis.</OtherInformation><Objective><Name/><Description/><Identifier>_58c6032e-bbd4-11e6-8232-8cd8f7e90587</Identifier><SequenceIndicator/><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><PublicationDate>2016-12-06</PublicationDate><Source>http://files.constantcontact.com/311cbc2c401/29358b0c-5a58-4ba1-8aa4-0716037493b5.pdf</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></StrategicPlan>
