官术网_书友最值得收藏!

Updating your IR process to include cloud

Ideally, you should have one single incident response process that covers both major scenarios—on-premises and cloud. This means you will need to update your current process to include all relevant information related to the cloud.

Make sure that you review the entire IR life cycle to include cloud-computing-related aspects. For example, during the preparation, you need to update the contact list to include the cloud provider contact information, on-call process, and so on. The same applies to other phases:

  • Detection: Depending on the cloud model that you are using, you want to include the cloud provider solution for detection in order to assist you during the investigation (7).
  • Containment: Revisit the cloud provider capabilities to isolate an incident in case it occurs, which will also vary according to the cloud model that you are using. For example, if you have a compromised VM in the cloud, you may want to isolate this VM from others in a different virtual network and temporarily block access from outside.

For more information about incident response in the cloud, we recommend that you read Domain 9 of the Cloud Security Alliance Guidance (8).

主站蜘蛛池模板: 梁河县| 密云县| 西安市| 隆安县| 洛宁县| 平南县| 莱州市| 日照市| 前郭尔| 岳西县| 林甸县| 长子县| 古交市| 夏津县| 塔河县| 奇台县| 石门县| 鱼台县| 闽侯县| 渑池县| 鞍山市| 宜君县| 嫩江县| 工布江达县| 海兴县| 同仁县| 奉贤区| 锦屏县| 奈曼旗| 宜昌市| 静宁县| 梨树县| 罗田县| 黑水县| 涿州市| 尼勒克县| 宣城市| 临朐县| 岳西县| 金湖县| 霍州市|