Incident Response Activities - Response
NIST 800-61 characterizes these activities as Containment, Eradication and Recovery, where the ISO 27035 framework calls them Responses.
4 slides · 1 min read · Domain 7
Regardless, these are the actions by the organization to isolate the damage, eliminate the cause, and restore the affected systems that are at the heart of the incident response. The containment activities will vary depending on the type of incident.
However, organizational practices for documentation of the actions, proper communication, escalation decisions and evidence preservation must be considered and applied to the circumstance.
Eliminating the source of the incident is as essential as addressing the effects. If the source is able to repeat the compromise, the incident response team will forever be fixing the same problem. Consequently, formal processes to identify the root cause of the incident should be applied in the response phase. Some of these root cause analysis techniques are listed in the table.
Text on this slide
Route Cause Analysis Technique
Pareto Analysis
Five Whys
Fishbone (Ishikawa) diagrams
Failure Mode Effects Analysis
Fault Trees
Description
80% of the value from 20% of the effort
Ask, "Why did this happen?" to determine the cause
Visualization tool focusing on causes
Systematically identify failures in components
Applies Boolean logic to identify failures
Root Cause Analysis Techniques
Restoration of services to normal condition is the ultimate end state. In some cases, service reductions or workarounds may be necessary. Regardless, appropriate communications must be continued until the normal operations resume.
