Steps/Phases of Incident Response Confusion
Reviewing my study notes and comparing them to answers from practice questions I've noticed some confusion. My notes from Conrad's book list the following steps:
Thanks!
- Preparation
- Detection and Analysis
- Containment, Eradication, and Recovery
- Post Incident Activity
- Triage
- Notification and identification
- Action/reaction
- Containment, analysis, tracing
- Follow-up
- Repair, recovery, prevention
Thanks!
Comments
-
cyberguypr Mod Posts: 6,928 ModCheck out NIST 800-61. It lists the 4 steps Conrad mentions. Where is that practice question from?
-
gespenstern Member Posts: 1,243 ■■■■■■■■□□ISC2 version should be PICERL, which is Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned, at least that's how I remember it.
But really, I always hated these stupid frameworks because they are non-technical and somewhat far from reality, allowing everybody and their grandma to have their own opinion, replace some steps with something different, etc. -
hylaab Member Posts: 35 ■■□□□□□□□□I would follow ISC2 way:
triage
notification and identification
action/reaction
containment, analysis, tracing
follow-up
repair, recovery, prevention -
g33k3r Member Posts: 249 ■■□□□□□□□□Thanks for everyone's feedback! The question was from Transenders. Looks like I'll have to make a mental note of both NIST and ISC2.