Containment, Eradication and Recovery Flashcards
3rd Phase of Incident Response Plan
Containment
reduce or eliminate the spread of the incident; includes preserving evidence
Eradication
return all systems to a known good state; rebuild systems
Recovery
identify the relevant attack vectors and implement countermeasures
What criteria you need to consider in Containment
Scope
Segmentation (micro)
Isolation
Removal
To Remove or Not Remove
Threat Intelligence value
Crime Scene Evidence
Ability to restore
What criteria you need to consider in Eradication?
All systems returned to a known good state
Be sure to gather Evidence first
Rebuild instead of repair
What criteria you need to consider in Recovery?
Vulnerability mitigations
Sanitization
Reconstruction
Secure Disposal
Patching - vendor specific patch requirement
Permissions
Factors for Considerations
Impact
Isolation
remediation
Compensating controls