Incident Response

Structured management of security incidents executed by a Computer Security Incident Response Team (CSIRT) using a risk matrix (urgency and impact) for criticality assessment.

Process Phases

  1. Preparation: Ensure plans, policies, and resources are in place.
  2. Identification: Accurately identify the threat and the actor.
  3. Containment: Isolate the threat to limit damage.
  4. Eradication: Eliminate the threat from the system.
  5. Recovery: Restore systems to normal operation.
  6. Lessons Learned: Analyze the incident and improve processes.