Incident response – Response/mitigation: Response refers to the actions taken to address the incident and minimize its impact. This may include isolating affected systems, blocking access to malicious websites, or restoring data from backups. Mitigation involves taking steps to prevent future incidents from occurring, such as patching vulnerabilities or implementing additional security measures. For example, a company may use firewalls to block incoming traffic from known malicious IP addresses or implement two-factor authentication to improve the security of user accounts.
Categories: CC D5: Security Operations | CCSP D5: Cloud Security Operations | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D4: Security Operations | SSCP D4: Incident Response and Recovery
« Back to Glossary Index