| By Kerry Thompson BSc.,CISSP,CCNA |
|---|
|
Picture this scenario: you arrive to work on
Monday morning to find problems on your network. You can't login, some servers
seem to be down, and the phone is going crazy. You consider the possibility of
two causes :
What you do next is critical. Every decision you
now make means a huge difference to the productivity of your business. This
paper presents a short list of what needs to be done to address this situation :
you have a security problem, it may be malicious hackers, or it could an
entirely accidental problem. Notify the appropriate people Stop the incident if it is still in
progress Identify the single most important and
immediate problem Preserve evidence from the incident Wipe out all effects of the incident Identify and mitigate all vulnerabilities
that were exploited Confirm that operations have been restored
to normal Create a final report Learn from the situation |
Best Practices for Security Incident Response
Recommend Us

