As the full-incident response team assembles, they move from the isolation and quarantine strategy into a full-incident mitigation mode by performing a full range of incident containment activities. In this video, learn about the process of incident mitigation, including damage and loss control.
- As the full incident response team assembles,…they move from the isolation…and quarantine strategy used by first responders…into a full incident mitigation mode.…The goal of this mitigation phase…is controlling the damage and loss…caused to the organization…by performing a full range…of incident containment activities.…The nature of those activities will vary…based upon the severity of the incident.…The National Institute for Standards and Technology…suggests six criteria that responders may use…when evaluating a potential containment strategy.…
First, responders should consider the potential…for damage and theft of resources during the incident.…Second, they should evaluate the need…for evidence preservation…and the effects that the strategy might have…on the ability to preserve evidence.…Third, responders should evaluate…service availability requirements…and the impact of different containment…strategies on that service availability.…Fourth, responders must understand…the time and resources required…to implement any proposed containment strategy.…
- Building an incident response program
- Escalation and notification
- eDiscovery process
- Conducting investigations
- System and file forensics
- Reporting and documenting incidents
- Business continuity planning
- Validating backups
- Testing BC/DR plans
Skill Level Intermediate
Q: This course was updated on 06/01/2018. What changed?
A: We updated three videos, covering creating an incident response program, communications plan, and response team.
Insights from a Cybersecurity Professionalwith Mike Chapple32m 15s Intermediate
IT Security Foundations: Core Conceptswith Lisa Bock1h 13m Beginner
1. Incident Management
2. Investigations and Forensics
3. Business Continuity
4. Disaster Recovery
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.