Conducting Incident Management
The management of an incident involves a number of distinct stages that, in combination, form the incident response cycle. The stages are as follows:
- Detection
- Response
- Mitigation or Containment
- Eradication
- Recovery or Remediation
- Lessons learned
- Reporting
It would be a mistake to read these stages as a linear progression from one to the other. Sometimes, it is necessary to go backward to go forward. A good example of this is that, during mitigation or containment of an intrusion, you may discover that the attackers have managed to reach a different area in your environment, or the intrusion is larger and more serious than originally anticipated. This will generally kick off another response and mitigation step in a different area, although these occurrences will still be deemed part of the same cyber incident.
Although the incident response process is highly dynamic and can be adapted depending on the situation...