官术网_书友最值得收藏!

Best practices to optimize incident handling

You can't determine what's abnormal if you don't know what's normal. In other words, if a user opens a new incident saying that the server's performance is slow, you must know all the variables before you jump to a conclusion. To know if the server is slow, you must first know what's considered to be a normal speed. This also applies to networks, appliances, and other devices. To mitigate scenarios like this, make sure you have the following in place:

  • System profile
  • Network profile/baseline
  • Log-retention policy
  • Clock synchronization across all systems

Based on this, you will be able to establish what's normal across all systems and networks. This will be very useful when an incident occurs and you need to determine what's normal before starting to troubleshoot the issue from a security perspective.

主站蜘蛛池模板: 普宁市| 襄垣县| 新河县| 烟台市| 南召县| 阳谷县| 青阳县| 深水埗区| 会泽县| 苏州市| 洞头县| 长白| 织金县| 蓬莱市| 观塘区| 定日县| 胶南市| 精河县| 德安县| 黎平县| 芜湖县| 察隅县| 尼勒克县| 微山县| 郓城县| 商水县| 岫岩| 克东县| 固始县| 清新县| 宁明县| 吉木萨尔县| 竹山县| 万山特区| 司法| 宁阳县| 肥东县| 新兴县| 阳春市| 古田县| 新乡市|