The goal of the ninth stage, Containment and Recovery, is to minimize the
impact of the security incident and return the organization back to normal
operations. For any organization, it is important to contain the security
incident before it can spread and affect other resources or increase organizational
damage. This ninth stage, launched in parallel with the first stage
(Incident Security Consultation), is an important organizational strategy
typically invoked early in the course of handling a security incident. For
the network forensics examiner, the organization’s containment actions
(for example, shut down a system, disable a network port, disable certain
server or network functions) can alter the network environment and affect
the examiner’s ability to collect court-admissible evidence.
đang được dịch, vui lòng đợi..
