Đang lật trang.
Đang mở chương tiếp theo…
Này… tạo phong cách đọc riêng nhé.
Phông chữ và chủ đề nằm trong Giao diện. Hãy chọn điều dễ chịu cho mắt.
Đang mở chương tiếp theo…
Pause guardians, war rooms, and user alerts planned before a hack, not during one.
Đang kiểm tra khả năng đọc thành tiếng của trình duyệt…
Bài đọc này hiện có bằng tiếng Anh. Giao diện sử dụng ngôn ngữ bạn đã chọn.
Đọc bản gốc tiếng Anh →In the fields of computer security and information technology, computer security incident management involves the monitoring and detection of security events on a computer or computer network, and the execution of proper responses to those events. Computer security incident management is a specialized form of incident management, the primary purpose of which is the development of a well understood and predictable response to damaging events and computer intrusions.
Incident management requires a process and a response team which follows this process. In the United States, This definition of computer security incident management follows the standards and definitions described in the National Incident Management System (NIMS). The incident coordinator manages the response to an emergency security incident. In a Natural Disaster or other event requiring response from Emergency services, the incident coordinator would act as a liaison to the emergency services incident manager.
Good preparation includes the development of an incident response team (IRT). Skills need to be used by the IRT would be, penetration testing, computer forensics, network security, etc. The IRT should also keep track of trends in cybersecurity and modern attack strategies. A training program for end users is important as well as most modern attack strategies target users on the network.
This part of the incident response plan identifies if there was a security event. When an end user reports information or an admin notices irregularities, an investigation is launched. An incident log is a crucial part of this step. All of the members of the team should be updating this log to ensure that information flows as fast as possible. If it has been identified that a security breach has occurred the next step should be activated.
In this phase, the IRT works to isolate the areas that the breach took place to limit the scope of the security event. During this phase it is important to preserve information forensically so it can be analyzed later in the process. Containment could be as simple as physically containing a server room or as complex as segmenting a network to not allow the spread of a virus.
This is where the threat that was identified is removed from the affected systems. This could include deleting malicious files, terminating compromised accounts, or deleting other components. Some events do not require this step, however it is important to fully understand the event before moving to this step. This will help to ensure that the threat is completely removed.
Được chọn lọc và định dạng lại từ Computer security incident management, do các cộng tác viên biên soạn, theo CC BY-SA 4.0. Bản sửa đổi 1367219842. Các phần và định dạng đã được rút gọn; bản sửa đổi được liên kết cung cấp bối cảnh đầy đủ và lịch sử đóng góp. Nội dung tham khảo này giữ nguyên giấy phép. Các liên kết trích dẫn bổ sung được nhập từ bản sửa đổi đó và chưa được kiểm tra độc lập tại đây.