1. Prerequisites
- Report of a lost, misplaced, or stolen device
- Device identifier available:
- Hostname
- Serial number
- Asset tag
- Mobile device identifier
- User information available
- Access to asset inventory
- Access to MDM or endpoint management platform
- Access to EDR platform
- Access to Identity Provider (IdP)
- Access to SIEM
- Incident ticket created
2. Step-by-Step Instructions
-
Collect Initial Incident Information
- Obtain:
- Reporting user
- Device type
- Asset identifier
- Date and time last seen
- Last known location
- Circumstances of loss or theft
- Record all details in the incident ticket.
- Obtain:
-
Validate Asset Ownership
- Confirm:
- Device is organisationally owned or managed
- Assigned user
- Business unit
- Asset status
- Verify information against the asset inventory.
- Confirm:
-
Determine Device Classification
- Identify whether the asset is:
- Laptop
- Desktop
- Mobile phone
- Tablet
- Removable media
- Other managed device
- Document the device classification.
- Identify whether the asset is:
-
Review Device Management Status
- Determine whether the device:
- Is enrolled in MDM
- Is enrolled in EDR
- Has full disk encryption enabled
- Is actively reporting telemetry
- Has remote lock or wipe capability
- Document all security controls currently applied.
- Determine whether the device:
-
Identify Last Known Device Activity
- Review:
- MDM telemetry
- EDR telemetry
- Authentication logs
- VPN logs
- Network activity
- Determine:
- Last check-in time
- Last known IP address
- Last known geographic location
- Last authenticated user
- Review:
-
Assess Loss vs Theft Indicators
- Determine whether available evidence suggests:
- Misplacement
- Accidental loss
- Theft
- Unauthorised possession
- Document observations and supporting evidence.
- Determine whether available evidence suggests:
-
Review Recent Authentication Activity
- Review:
- Successful logins
- Failed logins
- MFA events
- Session activity
- Geographic anomalies
- Identify any indicators of unauthorised use.
- Review:
-
Assess Preliminary Risk
- Consider:
- Device encryption status
- Privileged access assigned to the user
- Access to sensitive systems
- Access to regulated data
- Device management status
- Evidence of unauthorised activity
- Assign a preliminary incident severity.
- Consider:
-
Determine Required Response Actions
- Determine whether the incident requires:
- Device Security Posture Assessment
- Device Data Exposure Assessment
- Account containment
- Session revocation
- Remote lock
- Remote wipe
- Escalation to Physical Security
- Document recommended next actions.
- Determine whether the incident requires:
-
Escalate and Hand Off
- Provide findings to the Incident Commander and Technical Lead.
- Update incident severity if required.
- Escalate to:
- Analysis activities
- Containment activities
- Physical Security investigation (if applicable)
- Update the incident record with all findings.
3. Post-Action
- Ensure all device identifiers are documented.
- Ensure all asset ownership information is recorded.
- Preserve relevant authentication and device telemetry.
- Document risk assessment findings and supporting evidence.
- Attach all validation findings to the incident record.
- Ensure required analysis and containment activities have been initiated.
- Participate in subsequent investigation activities as required.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
