错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Incident Handling and System Availability

  • Robin Sharp

摘要

This chapter 1 focuses on how to react if, despite all precautions, an attack or other incident leads to a security breach. This is largely a question of planning. Firstly, to ensure that all security breaches, large or small, are registered so suitable action can be taken. Secondly, by planning how to discover what has actually happened, if a breach is detected. And thirdly, planning how to restore the IT systems to a normal state so that daily operations can continue. It looks at forensic techniques used to investigate incidents which involve ordinary computers and the more specialised smartphones, and at how to deal with encrypted units. It introduces the discplines of Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP), and the NIST Cybersecurity Framework-Finally it reviews some methods for improving security awareness, so that all members of an organisation know what to do if an incident is detected.