jiffman1 / SOC

0 stars 0 forks source link

Incident Handling Process #1

Open jiffman1 opened 1 week ago

jiffman1 commented 1 week ago

1.An event is an action occurring in a system or network. e g mouse click, sending email

  1. An incident is an event with negative consequences. e.g unauthorized access, system crash, natural disaster like outage

  2. Incident Handling Process is a clearly defined set of procedures to manage and respond to security incidents in a computer or network engineer

  3. Incidents for IH process not limited to intrusions alone - availability issues, Loss of intellectual property/ data

  4. Incident Response life cycle involves Preparation -detection & analysis -containment -Eradication & recovery- Post incident activity