QuestionQ7

Incident Response and Business Continuity

Notifying system owners, requiring password changes for affected user accounts, and increasing monitoring to identify related malicious activity are part of which process?

Explanation

Incident recovery returns affected systems and accounts to normal, secure operation and helps prevent recurrence. It can include changing compromised passwords and increasing logging or network monitoring because previously attacked resources may be targeted again. NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!