is an unexpected event occurring when an attack, whether natural or human-made, affects information resources and/or assets, causing actual damage or disruption to a business’s assets.
incident
is a detailed set of processes that anticipate, detect, and mitigate the effects of an unexpected event that might compromise information resources and assets.
incident response plan (IRP)
the set of procedures, policies, and guidelines that commence at the detection of an incident
incident response (IR).
contingency plan (CP)
three major components of contingency plan (CP).
Incident Response
Disaster Recovery
Business Continuity
Personnel and Plan Preparation
company’s CISO
With the aid of other managers and systems administrators on the contingency planning (CP) team, the __ should select members from each community of interest to form an independent IR team, which executes the IRP.
CISO
Contingency planners
IRP, DRP, and BCP
six-step process when creating each of the three CP components [IRP, DRP, and BCP]:
During the incident
_ during the incident
After the incident
Incident Detection
Overloaded networks, computers, or servers, misbehaving computers systems or software packages
Before the incident
Incident Detection
_ IR team
Incident Detection
; intrusion detection systems (IDS), host- and network-based virus detection software, and systems administrators.
Incident Detection
possible, probable, and definite indicators.
Incident Response
_IR team
is designed to first stop the incident (if still continuing), mitigate its effects, and provide information for the recovery from the incident.
Incident Response
_IR
Incident Response
❑ Notification of Key personnel
❑ Documentation of an Incident
❑ Incident Containment strategies
Notification of key Personnel.
Incident Response