Salta ai contenuti

Incident Response

Questi contenuti non sono ancora disponibili nella tua lingua.

  • On-call rota, comms channels, and incident commander role defined.
  • Runbooks for common failures and data breaches.
  1. Detect: monitoring alerts, stakeholder reports, anomaly detection.
  2. Triage: classify severity, assign roles, start incident doc.
  3. Contain: disable risky flows, rotate keys, block exfil paths.
  4. Eradicate/Recover: fix root cause, restore, validate integrity.
  5. Notify: legal/compliance review; stakeholder and user comms as required.
  6. Postmortem: blameless review, action items, owners, and deadlines.
  • MTTR within target; actions prevent recurrence; comms timely and clear.
  • Role confusion: pre-assign and drill quarterly.
  • Hours to days depending on scope; protects trust and compliance.