LEADER 03158nam 22004095 450 001 9910300743803321 005 20240116112059.0 010 $a1484238702 024 7 $a10.1007/978-1-4842-3870-7 035 $a(CKB)4100000006674712 035 $a(MiAaPQ)EBC5521337 035 $a(DE-He213)978-1-4842-3870-7 035 $a(PPN)230542735 035 $a(CaSebORM)9781484238707 035 $a(EXLCZ)994100000006674712 100 $a20180920d2018 u| 0 101 0 $aeng 135 $aurcnu|||||||| 181 $ctxt$2rdacontent 182 $cc$2rdamedia 183 $acr$2rdacarrier 200 10$aCybersecurity Incident Response /$eHow to Contain, Eradicate, and Recover from Incidents /$fby Eric C. Thompson 205 $a1st ed. 2018. 210 1$aBerkeley, CA :$cApress :$cImprint: Apress,$d2018. 215 $a1 online resource (184 pages) 327 $aChapter 1: The Significance of Incident Response -- Chapter 2: Necessary Prerequisites -- Chapter 3: Incident Response Frameworks -- Chapter 4: Leadership, Teams, and Culture -- Chapter 5: The Incident Response Strategy -- Chapter 6: Cyber Risks and the Attack Lifecycle -- Chapter 7: Detection and Identification of Events -- Chapter 8: Containment -- Chapter 9: Eradication, Recovery, and Post-Incident Review -- Chapter 10: Continuous Monitoring of Incident Response Program -- Chapter 11: Incident Response Story -- Chapter 12: This Is a Full-Time Job -- Appendix A: NIST CSF. 330 $aCreate, maintain, and manage a continual cybersecurity incident response program using the practical steps presented in this book. Don't allow your cybersecurity incident responses (IR) to fall short of the mark due to lack of planning, preparation, leadership, and management support. Surviving an incident, or a breach, requires the best response possible. This book provides practical guidance for the containment, eradication, and recovery from cybersecurity events and incidents. The book takes the approach that incident response should be a continual program. Leaders must understand the organizational environment, the strengths and weaknesses of the program and team, and how to strategically respond. Successful behaviors and actions required for each phase of incident response are explored in the book. Straight from NIST 800-61, these actions include: Planning and practicing Detection Containment Eradication Post-incident actions What You?ll Learn: Know the sub-categories of the NIST Cybersecurity Framework Understand the components of incident response Go beyond the incident response plan Turn the plan into a program that needs vision, leadership, and culture to make it successful Be effective in your role on the incident response team. 606 $aData protection 606 $aSecurity$3https://scigraph.springernature.com/ontologies/product-market-codes/I28000 615 0$aData protection. 615 14$aSecurity. 676 $a005.8 700 $aThompson$b Eric C$4aut$4http://id.loc.gov/vocabulary/relators/aut$0917128 906 $aBOOK 912 $a9910300743803321 996 $aCybersecurity Incident Response$92528341 997 $aUNINA