Incident response is the organized approach to handling security incidents so that damage, cost and recovery time are minimized. The widely used NIST incident handling model, described in Special Publication 800-61, groups the work into phases: preparation; detection and analysis; containment, eradication and recovery; and post-incident activity, often called lessons learned. The SSCP outline lists containment, eradication and recovery as separate steps, and you should know their order and purpose.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.