Phases of an incident response playbook Flashcards
1
Q
- Preparation
A
Before incidents occur, mitigate potential impacts on the organization by documenting, establishing staffing plans, and educating users.
2
Q
- Detection and analysis
A
Detect and analyze events by implementing defined processes and appropriate technology.
3
Q
- Containment
A
Prevent further damage and reduce immediate impact of incidents.
4
Q
- Eradication and recovery
A
Completely remove artifacts of the incident so that an organization can return to normal operations.
5
Q
- Post-incident activity
A
Document the incident, inform organizational leadership, and apply lessons learned.
6
Q
- Coordination
A
Report incidents and share information throughout the response process, based on established standards.
7
Q
A
8
Q
A