Incident Response
Questi contenuti non sono ancora disponibili nella tua lingua.
Prerequisites
Section titled “Prerequisites”- On-call rota, comms channels, and incident commander role defined.
- Runbooks for common failures and data breaches.
- Detect: monitoring alerts, stakeholder reports, anomaly detection.
- Triage: classify severity, assign roles, start incident doc.
- Contain: disable risky flows, rotate keys, block exfil paths.
- Eradicate/Recover: fix root cause, restore, validate integrity.
- Notify: legal/compliance review; stakeholder and user comms as required.
- Postmortem: blameless review, action items, owners, and deadlines.
Validation
Section titled “Validation”- MTTR within target; actions prevent recurrence; comms timely and clear.
Troubleshooting
Section titled “Troubleshooting”- Role confusion: pre-assign and drill quarterly.
Time/Impact
Section titled “Time/Impact”- Hours to days depending on scope; protects trust and compliance.