From the course: Complete Guide to Cybersecurity: A Practical Approach

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Understanding the incident response process

Understanding the incident response process

- [Instructor] Incident response is a systemic approach to addressing and managing the aftermath of a security breach or a cyber attack. The goal of incident response is to effectively manage the incident, minimize the impact to the organization, and prevent future recurrences, right? So a well-defined incident response process will help you to quickly identify, to quickly contain, to quickly eradicate and recover from cyber threats, basically reducing the overall risk and potential damage to the organization. One of the most comprehensive and useful resources around incident response and that defines the incident response process is the NIST Special Publication 800-61 Revision 2, otherwise known as a Computer Security Incident Handling Guide. The incident response process consists of several steps. The first one is preparation, then detection and analysis, containment, eradication, and recovery and post-incident activity. Preparation is the foundation of an effective incident…

Contents