For the third phase, containment and eradication, we are establishing guidelines on whether an event requires evidence collection, damage assessment and identification of the attackers. We are also preparing checklists to help ensure proper eradication and containment of whatever malicious activity the incident involves. For example, a checklist might address what to do when a Windows server is compromised.
For the post-incident phase, we are describing how to ensure that we have gathered all the information necessary for criminal or administrative action, and we are including recommendations on post-mortems so we can identify what went well and what needs improvement.
Once the incident-response process document is complete, we'll start scheduling training sessions and then regular testing of the plan so we can maintain confidence that we are able to effectively respond to any incident.
Sign up for MIS Asia eNewsletters.