- Cybersecurity:Attack and Defense Strategies
- Yuri Diogenes Erdal Ozkaya
- 139字
- 2021-06-30 19:15:50
Best practices to optimize incident handling
You can't determine what's abnormal if you don't know what's normal. In other words, if a user opens a new incident saying that the server's performance is slow, you must know all the variables before you jump to a conclusion. To know if the server is slow, you must first know what's considered to be a normal speed. This also applies to networks, appliances, and other devices. To mitigate scenarios like this, make sure you have the following in place:
- System profile
- Network profile/baseline
- Log-retention policy
- Clock synchronization across all systems
Based on this, you will be able to establish what's normal across all systems and networks. This will be very useful when an incident occurs and you need to determine what's normal before starting to troubleshoot the issue from a security perspective.
推薦閱讀
- 無蘋果不生活 OS X Mountain Lion隨身寶典
- PLC控制系統應用與維護
- Implementing Azure DevOps Solutions
- Kali Linux 2018:Windows Penetration Testing
- NetDevOps入門與實踐
- Python UNIX和Linux系統管理指南
- Windows 8實戰從入門到精通(超值版)
- 分布式高可用架構之道
- 精解Windows 10
- Kali Linux高級滲透測試(原書第3版)
- Linux操作系統
- Zabbix監控系統之深度解析和實踐
- Java EE 8 High Performance
- Mastering Eclipse Plug-in Development
- 微軟360度