Incident Response
Structured management of security incidents executed by a Computer Security Incident Response Team (CSIRT) using a risk matrix (urgency and impact) for criticality assessment.
Process Phases
- Preparation: Ensure plans, policies, and resources are in place.
- Identification: Accurately identify the threat and the actor.
- Containment: Isolate the threat to limit damage.
- Eradication: Eliminate the threat from the system.
- Recovery: Restore systems to normal operation.
- Lessons Learned: Analyze the incident and improve processes.