错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Reacting to Cyber Incidents

  • Simon Tjoa,
  • Melisa Gafić,
  • Peter Kieseberg

摘要

While the design process of a system is fundamental in order to facilitate cyber resilience, incident handling is vital in order to be able to adapt the system to counter successful or promising attacks. Thus, in this chapter, we provide an overview of gathering threat information. The main focus of this chapter lies in incident handling, covering the process starting with the preparation steps required, as well as detection, containment, and post-incident handling. Furthermore, we discuss the important topic of threat hunting with an overview of prominent approaches, together with a discussion on data sources. Since many complex systems, e.g., in the supply chain area, cover multiple organizations and will be relevant for NIS2, these two aspects are also discussed. The chapter finishes with a short introduction to disaster recovery as the final step in the incident-handling process.