From the course: Complete Guide to Cybersecurity: A Practical Approach
Unlock this course with a free trial
Join today to access over 24,900 courses taught by industry experts.
Understanding the incident response process
From the course: Complete Guide to Cybersecurity: A Practical Approach
Understanding the incident response process
- [Instructor] Incident response is a systemic approach to addressing and managing the aftermath of a security breach or a cyber attack. The goal of incident response is to effectively manage the incident, minimize the impact to the organization, and prevent future recurrences, right? So a well-defined incident response process will help you to quickly identify, to quickly contain, to quickly eradicate and recover from cyber threats, basically reducing the overall risk and potential damage to the organization. One of the most comprehensive and useful resources around incident response and that defines the incident response process is the NIST Special Publication 800-61 Revision 2, otherwise known as a Computer Security Incident Handling Guide. The incident response process consists of several steps. The first one is preparation, then detection and analysis, containment, eradication, and recovery and post-incident activity. Preparation is the foundation of an effective incident…
Contents
-
-
-
-
-
-
-
-
-
-
-
(Locked)
Module 2: Incident response, digital forensics, and threat hunting introduction39s
-
(Locked)
Learning objectives54s
-
(Locked)
Exploring how to get started in incident response6m 6s
-
(Locked)
Understanding the incident response process5m 46s
-
(Locked)
Defining playbooks and run book automation (RBA)10m 29s
-
(Locked)
Understanding cyber threat intelligence (CTI)10m 23s
-
(Locked)
Understanding data normalization3m 1s
-
(Locked)
Deconstructing universal data formats and 5-tuple correlation1m 19s
-
(Locked)
Understanding security monitoring fundamentals6m 32s
-
(Locked)
Surveying security monitoring tools13m 33s
-
(Locked)
-
-
-
-
-
-
-
-
-
-
-
-
-
-