The Incident Response Process

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/6

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

7 Terms

1
New cards

Step 1

Preparation. In this phase, you build the tools, processes, and procedures to respond to an incident

2
New cards

Step 2

Detection. This phase involves reviewing events to identify incidents

3
New cards

Step 3

Analysis. Once an event has been identified as potentially being part of an incident, it needs to be analyzed

4
New cards

Step 4

Containment. Once an incident has been identified, the incident response team needs to contain it to prevent further issues or damage

5
New cards

Step 5

Eradication. The eradication stage involves removing the artifacts associated with the incident

6
New cards

Step 6

Recovery. Restoration to normal is the heart of the recovery phase

7
New cards

In addition to these six steps,

organizations typically conduct a lessons learned session. These sessions are important to ensure that the organizations improve and do not make the same mistakes again