Incident Response Policies and Procedures Flashcards
What is an incident?
An incident is an event that disrupts normal business operations. An incident response plan outlines the steps to take following the discovery and confirmation of an incident.
Incident-response procedure
There are six steps, including: Preparation
Identification
Containment
Eradication
Recovery
Lessons learned
Preparation
Conduct training.
Conduct practice drills (mock data breaches).
Ensure all resources are approved and funded.
Identification
Determine if there is a breach or violation of your security policy.
Containment
Data preservation (drive seizure or copying).
Data integrity.
Chain of custody.
Eradication
Use only for other types of breaches:
Determine root cause of breach.
Remove malware.
Recovery
Reintroduce affected systems into production environment.
Re-imaging, restore from backup.
Monitor.
Lessons learned
Discuss the breach.
What has the incident-response team learned after implementation of the incident-response plan?
What can the team do better next time?