The goal of the ninth stage, Containment and Recovery, is to minimize theimpact of the security incident and return the organization back to normaloperations. For any organization, it is important to contain the securityincident before it can spread and affect other resources or increase organizationaldamage. This ninth stage, launched in parallel with the first stage(Incident Security Consultation), is an important organizational strategytypically invoked early in the course of handling a security incident. Forthe network forensics examiner, the organization’s containment actions(for example, shut down a system, disable a network port, disable certainserver or network functions) can alter the network environment and affectthe examiner’s ability to collect court-admissible evidence.
đang được dịch, vui lòng đợi..
