Reacting to Cyber Incidents
摘要
While the design process of a system is fundamental in order to facilitate cyber resilience, incident handling is vital in order to be able to adapt the system to counter successful or promising attacks. Thus, in this chapter, we provide an overview of gathering threat information. The main focus of this chapter lies in incident handling, covering the process starting with the preparation steps required, as well as detection, containment, and post-incident handling. Furthermore, we discuss the important topic of threat hunting with an overview of prominent approaches, together with a discussion on data sources. Since many complex systems, e.g., in the supply chain area, cover multiple organizations and will be relevant for NIS2, these two aspects are also discussed. The chapter finishes with a short introduction to disaster recovery as the final step in the incident-handling process.