From the course: Cyber Defense Infrastructure: Mitigating Cyber Risks and Preventing Security Incidents
Unlock this course with a free trial
Join today to access over 25,400 courses taught by industry experts.
Incident response frameworks
From the course: Cyber Defense Infrastructure: Mitigating Cyber Risks and Preventing Security Incidents
Incident response frameworks
- Unfortunately, despite the best attempts to proactively safeguard our environment, incidents will still occur. Just like with threat detection, following a well-structured IR or incident response framework will help ensure that your response efforts are consistent, comprehensive, and aligned with industry best practices. Frameworks also keep your team organized and provide a shared language for communicating when issues occur. First is the NIST Cybersecurity Framework, CSF. This is one of the most widely used guidelines in cybersecurity. It provides a risk-based approach to managing cybersecurity based on six core functions, identify, protect, detect, respond, recover, and govern. Next is the NIST Special Publication 800-61. It's also called the Computer Security Incident Handling Guide. SP 800-61 is a comprehensive guide focused on incident response, providing step-by-step instructions on different security incidents. It deepens the understanding of the incident's lifecycle and how…