Technology

Windows System Recovery and the NIST Cybersecurity Framework

Part 1

1. a) Create a system restore point for a Windows 10 system. To create a restore point in Windows, first launch Cortana and say, “Open the Control Panel.” After the Control Panel opens, select Recovery. On the next screen, select Configure System Restore. Next, turn the System Restore utility on, and everything is set. Click OK, and the system restore point will be created.

b) Use a specific system restore point to roll back changes made to a Windows 10 system. Open Cortana and search for Create a restore point. On the next screen, click on System Properties.

Click on the Next button, then select the most recent known working restore point. This helps to fix the problem. Click on the Scan for affected programs button, click Close, and then click the Next and Finish buttons, and the computer will be restored to its state before the event.

c) Delete system restore points from a Windows 10 system. Restore points are stored in the protected hidden OS. To delete restore points, search for the Control Panel, open the Control Panel, click on the Recovery icon, and click on Configure System Restore. Then, on the next screen, click on System Protection. From the protection setting, select a drive to delete all restore points, click on the Configure button, click on the Delete button, and click on the Continue button to confirm. Then close the window. When finished, the restore points will be deleted from the computer.

2. a) Incident response. First, the resources needed are defined, and a plan for the response before the occurrence highlights the framework to respond to the incident. Stop anything from being further removed. In case of hacking of a website, it is necessary to prevent further hacking by blocking communication channels like internet access to prevent further data access or data loss (NIST Cybersecurity Framework).

What happened after the hacking or the incident? Identify what has been done or changed or the data that has been stolen. Use system logs to identify what has happened. This can be achieved by running internet connectivity monitors. Then, identify the consequence of the data that has gone public, that is, data that has gone to a competitor domain in business. Rebuild, back up, and recover depending on what happened to the system or website. Get to know what was accessed without authorization, fix the vulnerable points to prevent any occurrence from happening again, and reset system passwords. Using the backup and the rebuilt system, recovery tools are used to recover the system to normal. The Windows registry is a database where all settings and operating systems are stored, and the OS’s components are programmed to use it. In occurrence, in the window, a key is added to the Windows registry. To back up the Windows registry, go to Start, search for regedit.exe, click on the registry key to back up, select File, and then Export and save the backup (NIST Cybersecurity Framework).

b) Blocking network requests – minimizing administrator privileges limits the execution of content that requires registry modifications. This prevents unauthorized system configuration changes. Also, use monitor mode, which provides logs of changes executed (NIST Cybersecurity Framework).

Ensure the files that have been accessed are in a good version, as well as the creation and modification date. Monitor the changes made by the unauthorized access and reconcile changes. Focus on the priority and take action before more damage is done to the file (NIST Cybersecurity Framework).

c) In Windows 10, go to Start > Settings > Update and Security > Recovery, click Get started, and then click on Reset this PC. On the next screen, click on Keep My Files, choose the files to remove, and confirm your action.

d) Cleaning of the Control Panel using the Windows registry. You can remove installed apps and changes at HKEY_LOCAL_MACHINE\SOFTWARE\windows\currentVersion\uninstall. Identify the applications to remove and delete them by deleting their keys.

Part 2

Use the local group policy in Windows 10 to prevent automatic updates: use the Windows key + R, type gpedit.msc, and browse to Windows Update. Right-click Configure Automatic Updates, enable the policy, and choose Auto Download and Notify for Install. Click Apply and OK to complete. Plan the incident response by assessing threat detection and conducting cyber-hunting practice. After preparation, monitor event occurrence to detect any incidents and issue an alert. After the event is analyzed, coordinate the shutdown of the device. Rebuild the OS and change the passwords for all accounts. After the rebuild, complete the documentation, update threat intelligence, and create preventive measures to prevent future incidents. The following are notes, warnings, and restrictions to put in place: turn off compatibility view, turn off Windows Defender and other Microsoft networks, turn off automatic download and installation of applications, and do not allow automatic update location. Turn off all automatic updates of Microsoft features and specify the Microsoft intranet update service location. Turn off the automatic download of the ActiveX version list. For a tailored experience, do not use diagnostic data and enable the NTP client (NIST Cybersecurity Framework).

Also, protect the clipboard and what is copied in it, ensure browsing protection through input spoofing, and protect messages from queueing.

Reference

https://www.nist.gov/programs-projects/cybersecurity-framework

https://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructurecybersecurity

https://www.federalregister.gov/articles/2013/02/26/2013-04413/developing-a-framework-to-improvecritical-infrastructure-cybersecurity

https://csrc.nist.gov/cyberframework/rfi_comments.html

https://csrc.nist.gov/cyberframework/nist-initial-analysis-of-rfi-responses.pdf https://www.nist.gov/itl/csd/cybersecurity-framework-workshop.cfm https://www.nist.gov/itl/csd/cybersecurity-framework-workshop-may-29-31-2013.cfm https://www.nist.gov/itl/upload/draft_outline_preliminary_framework_standards.pdf https://www.nist.gov/itl/csd/3rd-cybersecurity-framework-workshop-july-10-12-2013-san-diego-ca.cfm https://www.nist.gov/itl/upload/draft_framework_core.pdf

Editorial Staff Image

Academic Master Education Team is a group of academic editors and subject specialists responsible for producing structured, research-backed essays across multiple disciplines. Each article is developed following Academic Master’s Editorial Policy and supported by credible academic references. The team ensures clarity, citation accuracy, and adherence to ethical academic writing standards

Content reviewed under Academic Master Editorial Policy.

SEARCH

WHY US?
Calculator 1

Calculate Your Order




Standard price

$310

SAVE ON YOUR FIRST ORDER!

$263.5

YOU MAY ALSO LIKE