Incident Response Activities - Response

NIST 800-61 characterizes these activities as Containment, Eradication and Recovery, where the ISO 27035 framework calls them Responses.

4 slides · 1 min read · Domain 7

Slide 1

Regardless, these are the actions by the organization to isolate the damage, eliminate the cause, and restore the affected systems that are at the heart of the incident response. The containment activities will vary depending on the type of incident.

However, organizational practices for documentation of the actions, proper communication, escalation decisions and evidence preservation must be considered and applied to the circumstance.

Eliminating the source of the incident is as essential as addressing the effects. If the source is able to repeat the compromise, the incident response team will forever be fixing the same problem. Consequently, formal processes to identify the root cause of the incident should be applied in the response phase. Some of these root cause analysis techniques are listed in the table.

Text on this slide

Route Cause Analysis Technique

Pareto Analysis

Five Whys

Fishbone (Ishikawa) diagrams

Failure Mode Effects Analysis

Fault Trees

Description

80% of the value from 20% of the effort

Ask, "Why did this happen?" to determine the cause

Visualization tool focusing on causes

Systematically identify failures in components

Applies Boolean logic to identify failures

Root Cause Analysis Techniques

Restoration of services to normal condition is the ultimate end state. In some cases, service reductions or workarounds may be necessary. Regardless, appropriate communications must be continued until the normal operations resume.

Test this domain