Incident‐Response Planning
Chris Moschovitis
Abstract
Chris Moschovitis
Abstract
Federal Information Security Management Act (FISMA) was signed into law in 2002, and it essentially requires all federal agencies to develop an incident-response plan. A small company may have an incident-response plan that calls for identifying an incident and immediately calling in outside expertise. A larger firm may have multiple incident-response specialists in house. The first critical thing to understand is that incident response is a program in and of itself. As such, it has its own distinct phases, and much like the overall cybersecurity program, it, too, is a living program. The core phases of incident-response planning are: preparing for incidents, identifying the occurrence of an incident, containing the incident, treating the incident, recovering from the incident, and post-incident review, aka the lessons-learned phase. To properly prepare for an incident, an executive need to have in place three things: business continuity (BC) plan, disaster recovery (DR) plan, and incident-response (IR) plan.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Federal Information Security Management Act (FISMA) was signed into law in 2002, and it essentially requires all federal agencies to develop an incident-response plan. A small company may have an incident-response plan that calls for identifying an incident and immediately calling in outside expertise. A larger firm may have multiple incident-response specialists in house. The first critical thing to understand is that incident response is a program in and of itself. As such, it has its own distinct phases, and much like the overall cybersecurity program, it, too, is a living program. The core phases of incident-response planning are: preparing for incidents, identifying the occurrence of an incident, containing the incident, treating the incident, recovering from the incident, and post-incident review, aka the lessons-learned phase. To properly prepare for an incident, an executive need to have in place three things: business continuity (BC) plan, disaster recovery (DR) plan, and incident-response (IR) plan.
Key concepts: Incident response, Incident management, Incident report, Plan (archaeology), AKA, Emergency response, Business, Computer security