Zusammenfassung der Ressource
Incident Response
- Incident Phase
- Preparation
- CSIRT
Anmerkungen:
- * Establish and maintains the incident response plan
* Make sure the team members understand the plan
Test the plan
Get management approve to the plan
- Detection And Analysis
- Incident
Analysis
- Containment, Eradication, Recovery
- Containment: Isolate the infected system
- Eradication: Eradicate the system
- Recovery: After remedition recover all the system
- Post-Incident Follow up
- Disaster Recovery
- Types
- Natural Disasters
- Human- Caused
- Disaster Recovery
Plans(DRP)
- Disaster Recovery Controls
- Preventing Controls
- Detective
Controls
- Corrective Controls
- Test/Trainings
- Table Top
- Functional test
- Operational
- Business Cont Plan
- Business Cont Planning
- RTO - Recovery Time Objective
- RPO - Recovery Point Objective
- MTTR- Mean TIme To Repair
- Mean Time Between Failures
- Business Cont Considarations
- Digital Forensics
- Evidence
- Identifying and acquiring
- Data
Acquisition
- System Images
- Network Traffic and logs
- Surveillance Videos
- Hashes Or
Checksums
- photos of scene
- Witness interveiwed
- Protecting and Storing
- Chain Of Custody
- Digital Forensic Devices
- leave in the current power state
- Disconnect from Network
- Refrain from opening file or applications
- Order Of volatility
- CPU
storage
- Process and Routing tables
- Kernel
Operations
- System
Storage
- Temp Files
- Fixed media
- Removable
devices
- Tape/DVD/Paper