An organization is updating its cybersecurity procedures to follow the standard NIST SP 800-61 incident response framework. In which sequential order should the cybersecurity team execute the four primary phases of the incident response lifecycle from beginning to end?
- 1Preparation
- 2Detection and Analysis
- 3Containment, Eradication, and Recovery
- 4Post-Incident Activity
Cevap
The correct sequential order of the NIST incident response lifecycle phases is Preparation, followed by Detection and Analysis, followed by Containment, Eradication, and Recovery, and ending with Post-Incident Activity.
According to the NIST SP 800-61 guidelines, the standard incident response lifecycle proceeds sequentially through four main phases: Preparation (setting up plans and capabilities), Detection and Analysis (discovering and investigating the security event), Containment, Eradication, and Recovery (limiting impact, eliminating the threat, and restoring systems), and Post-Incident Activity (reviewing lessons learned to refine future response).
Adım Adım Çözüm
Anahtar Kavram
NIST SP 800-61 Incident Response Lifecycle Phases