2018Unpublished venueRequires access

Incident‐Response Planning

Chris Moschovitis

Open publisher page 1 citations

Abstract

Federal Information Security Management Act (FISMA) was signed into law in 2002, and it essentially requires all federal agencies to develop an incident-response plan. A small company may have an incident-response plan that calls for identifying an incident and immediately calling in outside expertise. A larger firm may have multiple incident-response specialists in house. The first critical thing to understand is that incident response is a program in and of itself. As such, it has its own distinct phases, and much like the overall cybersecurity program, it, too, is a living program. The core phases of incident-response planning are: preparing for incidents, identifying the occurrence of an incident, containing the incident, treating the incident, recovering from the incident, and post-incident review, aka the lessons-learned phase. To properly prepare for an incident, an executive need to have in place three things: business continuity (BC) plan, disaster recovery (DR) plan, and incident-response (IR) plan.

About this research paper

What this paper is about

Federal Information Security Management Act (FISMA) was signed into law in 2002, and it essentially requires all federal agencies to develop an incident-response plan. A small company may have an incident-response plan that calls for identifying an incident and immediately calling in outside expertise. A larger firm may have multiple incident-response specialists in house. The first critical thing to understand is that incident response is a program in and of itself. As such, it has its own distinct phases, and much like the overall cybersecurity program, it, too, is a living program. The core phases of incident-response planning are: preparing for incidents, identifying the occurrence of an incident, containing the incident, treating the incident, recovering from the incident, and post-incident review, aka the lessons-learned phase. To properly prepare for an incident, an executive need to have in place three things: business continuity (BC) plan, disaster recovery (DR) plan, and incident-response (IR) plan.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Federal Information Security Management Act (FISMA) was signed into law in 2002, and it essentially requires all federal agencies to develop an incident-response plan. A small company may have an incident-response plan that calls for identifying an incident and immediately calling in outside expertise. A larger firm may have multiple incident-response specialists in house. The first critical thing to understand is that incident response is a program in and of itself. As such, it has its own distinct phases, and much like the overall cybersecurity program, it, too, is a living program. The core phases of incident-response planning are: preparing for incidents, identifying the occurrence of an incident, containing the incident, treating the incident, recovering from the incident, and post-incident review, aka the lessons-learned phase. To properly prepare for an incident, an executive need to have in place three things: business continuity (BC) plan, disaster recovery (DR) plan, and incident-response (IR) plan.

Key concepts: Incident response, Incident management, Incident report, Plan (archaeology), AKA, Emergency response, Business, Computer security

Related papers

Back to paper searchBrowse research topicsOriginal source
Incident‐Response Planning — Research Paper | ScholarLens