Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
Skills in this repository
CyberStrikeus/CyberStrike - Page 111
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Public updates on incident recovery are shared using approved methods and messaging
Recovery plans incorporate lessons learned
Recovery strategies are updated
The recovery portion of the incident response plan is executed once initiated from the incident response process
Recovery actions are selected, scoped, prioritized, and performed
The integrity of backups and other restoration assets is verified before using them for restoration
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
The end of incident recovery is declared based on criteria, and incident-related documentation is completed
Improvements
Investigations are conducted to ensure effective response and support forensics and recovery activities
Responses to detected cybersecurity incidents are managed
Activities are performed to prevent expansion of an event and mitigate its effects
Response Planning
Notifications from detection systems are investigated
The impact of the incident is understood
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
Incidents are categorized consistent with response plans
Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g.
Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
Incident data and metadata are collected, and their integrity and provenance are preserved
An incident's magnitude is estimated and validated
Personnel know their roles and order of operations when a response is needed
Internal and external stakeholders are notified of incidents
Information is shared with designated internal and external stakeholders
Coordination with stakeholders occurs consistent with response plans
Voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness
Response plans incorporate lessons learned
Response strategies are updated
The incident response plan is executed in coordination with relevant third parties once an incident is declared
Incident reports are triaged and validated
Incidents are categorized and prioritized
Incidents are escalated or elevated as needed
The criteria for initiating incident recovery are applied
Incidents are contained
Incidents are eradicated
Newly identified vulnerabilities are mitigated or documented as accepted risks
Response plan is executed during or after an incident
Access Enforcement