Certified Information Security Manager (CISM)Incident ManagementEasy
An organization experiences a ransomware attack that encrypts critical servers. The incident response team successfully contains the spread and eradicates the malware. What is the NEXT logical step according to the typical incident response lifecycle?
- AInitiate forensic analysis of affected systems.
- BUpdate firewall rules to prevent re-infection.
- CRestore data and systems from backup.
- DConduct a post-incident review meeting.
Show answer & explanationAnswer & explanation
Correct answer: C. Restore data and systems from backup.
After containing and eradicating the threat, the next logical step in the incident response lifecycle is recovery, which involves restoring affected systems and data to normal operations. Forensic analysis often runs concurrently or is initiated before eradication to gather evidence, but full restoration is the immediate priority after the threat is removed.
Why the other options are wrong
- A. Forensic analysis is often part of identification and containment, but full restoration is the next immediate step after eradication.
- B. Updating security controls like firewall rules is part of eradication or post-incident activity, but recovery is the immediate next step.
- D. A post-incident review is a crucial final step, but it occurs after full recovery and normal operations have resumed.
Incident Response Lifecycle
A structured approach to managing security incidents from preparation through post-incident activities.
- Typically includes Preparation, Identification, Containment, Eradication, Recovery, and Post-Incident Activity.
- Ensures systematic handling of incidents.
- Aims to minimize impact and prevent recurrence.
Memory trick: PICERL: Prepare, Identify, Contain, Eradicate, Recover, Lessons.