Learning Objectives:
-
Understand the principles of containment, eradication, and recovery in cyber incident management.
-
Apply containment strategies to limit the spread of cyber incidents.
-
Implement eradication strategies to remove the threat from affected systems.
-
Develop recovery strategies to restore normal operations.
3.1 Containment – Limiting the Spread of the Incident
Containment is the process of limiting the spread of a cyber incident to prevent further damage. The Coursera course teaches participants to “implement structured containment, eradication, and recovery strategies to manage active security incidents and restore affected systems” . The course covers “isolating compromised hosts to limit attacker movement” .
The FSB’s framework identifies mitigation as a key component of incident response, which “prevents the aggravation of the situation and eradicates cyber-threats in a timely manner to alleviate their impact on business operations and services” .
Key Containment Strategies:
-
Network Segmentation: Isolating affected network segments to prevent lateral movement.
-
System Isolation: Isolating compromised systems to prevent further compromise.
-
Access Revocation: Revoking access credentials that may have been compromised.
-
Temporary Shutdown: Temporarily shutting down affected systems to prevent further damage.
3.2 Eradication – Removing the Threat
Eradication is the process of removing the threat from affected systems. The Coursera course covers “removing malicious artifacts” and “validating system integrity before returning services to operation” .
Key Eradication Strategies:
-
Malware Removal: Removing malware from affected systems.
-
Patch Application: Applying patches to address vulnerabilities.
-
System Rebuilding: Rebuilding compromised systems from known-good backups.
-
Credential Resetting: Resetting credentials that may have been compromised.
-
Validation: Validating system integrity after eradication.
3.3 Recovery – Restoring Normal Operations
Recovery is the process of restoring normal operations after a cyber incident. The Coursera course covers “recovery strategies to manage active security incidents” and “validating system integrity before returning services to operation” . The course also covers “evaluating post-incident lessons learned and operational metrics to improve response effectiveness, strengthen defenses, and enhance long-term organizational resilience” .
Key Recovery Strategies:
-
System Restoration: Restoring systems from known-good backups.
-
Data Recovery: Recovering data from backups.
-
Service Restoration: Restoring services to operation.
-
Validation: Validating system integrity after recovery.
-
Resumption: Resuming normal operations.
The FSB’s framework identifies restoration as a key component of incident response, which “repairs and restores systems or assets affected by a cyber-incident to safely resume business-as-usual delivery of impacted services” .
3.4 Recovery Testing and Validation
Testing and validation are essential for ensuring that recovery is successful. The Coursera course covers “validating recovery processes and measuring resilience improvements” .
Key Testing Activities:
-
Backup Testing: Testing backups to ensure they can be restored.
-
Recovery Testing: Testing recovery procedures to ensure they are effective.
-
System Validation: Validating system integrity after recovery.
-
Operational Validation: Validating that operations have been restored.