Incident Response Activities, From Recovery to Review

7 slides · 4 min read · Domain 7

Incident Response, From Recovery to Review

Incident response activities focus on identifying, containing, and resolving harmful events to minimize impact and restore normal operations.

Recovery, remediation, and post-incident review aim to restore operations, address root causes, and strengthen future response efforts.

Recovery

Recovery is the process by which the organization's IT infrastructure, applications, data, and workflows are reestablished and declared operational. In an ideal world, recovery starts when the eradication phase is complete, and the hardware, networks, and other systems elements are declared safe to restore to their required "normal" state. The ideal recovery process brings all elements of the system back to the moment in time just before the incident started to inflict damage or disruption to your systems. When recovery is complete, end users should be able to log back in and start working again, just as if they had last logged off at the end of a normal set of work-related tasks.

Remediation

Remediation activities involve corrective

These actions can occur at any point during actions to reduce the likelihood of a containment, eradication, or recovery similar incident recurring. These may depending on the nature of the attack include adjusting system configurations, and the specific remediations required. such as updating security control Each step in the recovery process must sensitivities, thresholds, or alarm settings, be validated to ensure it was correctly or rapidly resetting access credentials executed and fully completed. This like passwords and security challenge validation might involve simple checks responses. In some cases, remediation may of system status and health or more require completing overdue or improperly structured testing using predefined tools implemented updates to software, firmware, and procedures. For complex systems, or procedures. recovery may also require reinitializing components in a specific sequence to ensure proper functionality.

Reporting

One of the final tasks of the incident response team involves reporting to end users, functional managers, and senior leadership that the recovery operations are now complete. This communication marks an important transition point for both the organization and the Security Operations Center (SOC) team.

The response team then notifies management that systems are ready for normal operational use. Leadership is responsible for deciding when to formally return the organization from incident response status to standard business operations.

Once that notification has been endorsed by management and sent to those elements of the organization that need to know and act on it, the SOC transitions into a postincident set of activities, such as review and analysis of lessons learned.

Review and Improvement

Proper documentation and evidence

particularly challenging, as often the lessons handling will now become even more highlight the need for management to important as the organization evaluates its behave differently. Introspection is truly response to the event. If the organization difficult, and all levels of management decides to pursue civil or criminal sanctions, must assess their own willingness to change.

this phase may be delayed or performed in a way that does not compromise the legal

One of the common experiences in many action. If not, review of the event must professions is that processes are created be performed in a timely and consistent with lessons-learned steps that may manner.

produce quite a volume of meeting minutes In many cases, a lessons-learned meeting and a flurry of changes to be carried out in will help clarify the sequence of events and the administrative or other controls being used. While laudable, these steps do not identify areas for improvement. However, the organization must set an appropriate ensure that the organization and its people tone for the meeting. If individuals believe actually learn from an incident. Learning that the lessons-learned process will result should result in verifiable changes in in punishment, there is less likelihood that behavior. people will actively participate. A lessonsThis short overview of the principal activities learned meeting is not an inquisition. It is in incident response is by no means inclusive a learning event, and management must of all individual tasks necessary to effectively honor that expectation.

respond to an event. Proper communication, Once the lessons from the event have been documentation, and a willingness to change documented and properly reported, the processes that do not work are critical to report is available to management to drive incident response activities. process improvement activities. This is

Test this domain