Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
Idioma do texto original: inglês
Menu
Skills neste repositório
O SkillsMP coletou 7.442 skills de CyberStrikeus/CyberStrike. Abra uma skill para revisar a origem e os detalhes.
CyberStrikeus/CyberStrikeMostrando 40 de 7.442 skills coletadas.
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
Idioma do texto original: inglês
Public updates on incident recovery are shared using approved methods and messaging
Idioma do texto original: inglês
Recovery plans incorporate lessons learned
Idioma do texto original: inglês
Recovery strategies are updated
Idioma do texto original: inglês
The recovery portion of the incident response plan is executed once initiated from the incident response process
Idioma do texto original: inglês
Recovery actions are selected, scoped, prioritized, and performed
Idioma do texto original: inglês
The integrity of backups and other restoration assets is verified before using them for restoration
Idioma do texto original: inglês
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
Idioma do texto original: inglês
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
Idioma do texto original: inglês
The end of incident recovery is declared based on criteria, and incident-related documentation is completed
Idioma do texto original: inglês
Improvements
Idioma do texto original: inglês
Investigations are conducted to ensure effective response and support forensics and recovery activities
Idioma do texto original: inglês
Responses to detected cybersecurity incidents are managed
Idioma do texto original: inglês
Activities are performed to prevent expansion of an event and mitigate its effects
Idioma do texto original: inglês
Response Planning
Idioma do texto original: inglês
Notifications from detection systems are investigated
Idioma do texto original: inglês
The impact of the incident is understood
Idioma do texto original: inglês
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
Idioma do texto original: inglês
Incidents are categorized consistent with response plans
Idioma do texto original: inglês
Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g.
Idioma do texto original: inglês
Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
Idioma do texto original: inglês
Incident data and metadata are collected, and their integrity and provenance are preserved
Idioma do texto original: inglês
An incident's magnitude is estimated and validated
Idioma do texto original: inglês
Personnel know their roles and order of operations when a response is needed
Idioma do texto original: inglês
Internal and external stakeholders are notified of incidents
Idioma do texto original: inglês
Information is shared with designated internal and external stakeholders
Idioma do texto original: inglês
Coordination with stakeholders occurs consistent with response plans
Idioma do texto original: inglês
Voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness
Idioma do texto original: inglês
Response plans incorporate lessons learned
Idioma do texto original: inglês
Response strategies are updated
Idioma do texto original: inglês
The incident response plan is executed in coordination with relevant third parties once an incident is declared
Idioma do texto original: inglês
Incident reports are triaged and validated
Idioma do texto original: inglês
Incidents are categorized and prioritized
Idioma do texto original: inglês
Incidents are escalated or elevated as needed
Idioma do texto original: inglês
The criteria for initiating incident recovery are applied
Idioma do texto original: inglês
Incidents are contained
Idioma do texto original: inglês
Incidents are eradicated
Idioma do texto original: inglês
Newly identified vulnerabilities are mitigated or documented as accepted risks
Idioma do texto original: inglês
Response plan is executed during or after an incident
Idioma do texto original: inglês
Access Enforcement
Idioma do texto original: inglês