Die Seite wird umgeblättert.
Das nächste Kapitel kommt in Sicht…
Psst… lies auf deine Weise.
Schriften und Designs findest du unter Darstellung. Deine Augen entscheiden mit.
Das nächste Kapitel kommt in Sicht…
Pause guardians, war rooms, and user alerts planned before a hack, not during one.
Vorlesefunktion dieses Browsers wird geprüft…
Diese Lektüre ist derzeit auf Englisch verfügbar. Die Oberfläche verwendet deine gewählte Sprache.
Das englische Original lesen →In the fields of computer security and information technology, computer security incident management involves the monitoring and detection of security events on a computer or computer network, and the execution of proper responses to those events. Computer security incident management is a specialized form of incident management, the primary purpose of which is the development of a well understood and predictable response to damaging events and computer intrusions.
Incident management requires a process and a response team which follows this process. In the United States, This definition of computer security incident management follows the standards and definitions described in the National Incident Management System (NIMS). The incident coordinator manages the response to an emergency security incident. In a Natural Disaster or other event requiring response from Emergency services, the incident coordinator would act as a liaison to the emergency services incident manager.
Good preparation includes the development of an incident response team (IRT). Skills need to be used by the IRT would be, penetration testing, computer forensics, network security, etc. The IRT should also keep track of trends in cybersecurity and modern attack strategies. A training program for end users is important as well as most modern attack strategies target users on the network.
This part of the incident response plan identifies if there was a security event. When an end user reports information or an admin notices irregularities, an investigation is launched. An incident log is a crucial part of this step. All of the members of the team should be updating this log to ensure that information flows as fast as possible. If it has been identified that a security breach has occurred the next step should be activated.
In this phase, the IRT works to isolate the areas that the breach took place to limit the scope of the security event. During this phase it is important to preserve information forensically so it can be analyzed later in the process. Containment could be as simple as physically containing a server room or as complex as segmenting a network to not allow the spread of a virus.
This is where the threat that was identified is removed from the affected systems. This could include deleting malicious files, terminating compromised accounts, or deleting other components. Some events do not require this step, however it is important to fully understand the event before moving to this step. This will help to ensure that the threat is completely removed.
Ausgewählt und neu formatiert aus Computer security incident management, von den Mitwirkenden, unter CC BY-SA 4.0. Revision 1367219842. Abschnitte und Formatierung wurden gekürzt; die verlinkte Revision bietet den vollständigen Kontext und die Beitragshistorie. Der Referenztext behält seine Lizenz. Zusätzliche Quellenlinks stammen aus dieser Revision und wurden hier nicht unabhängig geprüft.