User Tools

Site Tools


incident_response

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

incident_response [2026/06/02 13:07] – created reidjsincident_response [2026/06/09 16:50] (current) reidjs
Line 1: Line 1:
 ====== Incident Response ====== ====== Incident Response ======
 Six steps Six steps
-1. prepare +  - 1. prepare: establish a formal incident response plan 
-2. identify +  2. identify: monitor network and system events, correlate alerts, and detect anaomalous behavior to confirm if a security incident has occurred 
-3. contain +  3. contain: isolate compromised systems to stop the attack from spreading  
-4. eradicate +  4. eradicate: remove the threat and eradicate the attacker's foothold, patch vulns that allowed the breach to happen 
-5. recovery +  5. recovery: restore clean sytems to production, verify they are operating normally, resume standard business practices 
-6. lessons learned+  6. lessons learned: analyze the incident to understand how the attacker got in
incident_response.txt · Last modified: by reidjs