Incident response process Flashcards
What is a incident?
This is where a security measure has been breached, and your company could be at risk
What is the incident response process
Preparation>Identification>Containment>Eradication>Recovery>Lessons learned
Incident Response Process-Idenetiofacaion
Analysis of events, components of this are monitoring, detecting, alerting, and logging
Containment - IRP
Response phase, interaction with affected systems, system shutdown, system isolation
Eradication - IRP
Running a deep scan and quarantine, then removal, wipe and load, verification of eradication
Recovery - IRP
Verification of eradication (required), rebuild from backups, reintroduce systems, restore back to normal state
Lessons learned - IRP
Ask questions, what went right? what went well? what went wrong? What was affected? How was it affected? How was the attack accomplished? What are the improvements that can be done