1/6
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
---|
No study sessions yet.
Step 1
Preparation. In this phase, you build the tools, processes, and procedures to respond to an incident
Step 2
Detection. This phase involves reviewing events to identify incidents
Step 3
Analysis. Once an event has been identified as potentially being part of an incident, it needs to be analyzed
Step 4
Containment. Once an incident has been identified, the incident response team needs to contain it to prevent further issues or damage
Step 5
Eradication. The eradication stage involves removing the artifacts associated with the incident
Step 6
Recovery. Restoration to normal is the heart of the recovery phase
In addition to these six steps,
organizations typically conduct a lessons learned session. These sessions are important to ensure that the organizations improve and do not make the same mistakes again