官术网_书友最值得收藏!

Best practices to optimize incident handling

You can't determine what's abnormal if you don't know what's normal. In other words, if a user opens a new incident saying that the server's performance is slow, you must know all the variables before you jump to a conclusion. To know if the server is slow, you must first know what's considered to be a normal speed. This also applies to networks, appliances, and other devices. To mitigate scenarios like this, make sure you have the following in place:

  • System profile
  • Network profile/baseline
  • Log-retention policy
  • Clock synchronization across all systems

Based on this, you will be able to establish what's normal across all systems and networks. This will be very useful when an incident occurs and you need to determine what's normal before starting to troubleshoot the issue from a security perspective.

主站蜘蛛池模板: 株洲县| 通化市| 沂南县| 温泉县| 丹阳市| 房产| 高雄县| 玉田县| 靖州| 吐鲁番市| 丰镇市| 马公市| 綦江县| 许昌市| 丹东市| 巍山| 昂仁县| 延长县| 台前县| 太仆寺旗| 来凤县| 巴彦淖尔市| 称多县| 博白县| 陈巴尔虎旗| 陇南市| 当涂县| 伊宁县| 正镶白旗| 微山县| 合作市| 长治县| 黄冈市| 昂仁县| 台东市| 陆丰市| 山阳县| 收藏| 清河县| 龙海市| 奉节县|