Phases of an Efficient Incident Response on Windows Infrastructure
What is an efficient incident response? The first thing that comes to mind is achieving the incident detection, verification, analysis, and handling activities defined in the SANS PICERL model at the lowest possible cost. All cybersecurity incidents lead to financial losses, which arise from a combination of impacts on the business, resource costs, and third-party involvement costs. Impacts on the business can be either fraud, extortion, or the impact caused by business downtime, forced underperformance, or reputational damage.
An incident can be discovered in the different phases of an attack that we discussed in the previous chapter. The earlier the detection happens, the more time the team has for their actions. That’s it. There is no point in complicating things.
What are the key ingredients of an effective incident response?
- Incident classification procedure
- Technical part of the incident...