官术网_书友最值得收藏!

Updating your IR process to include cloud

Ideally, you should have one single incident response process that covers both major scenarios—on-premises and cloud. This means you will need to update your current process to include all relevant information related to the cloud.

Make sure that you review the entire IR life cycle to include cloud-computing-related aspects. For example, during the preparation, you need to update the contact list to include the cloud provider contact information, on-call process, and so on. The same applies to other phases:

  • Detection: Depending on the cloud model that you are using, you want to include the cloud provider solution for detection in order to assist you during the investigation (7).
  • Containment: Revisit the cloud provider capabilities to isolate an incident in case it occurs, which will also vary according to the cloud model that you are using. For example, if you have a compromised VM in the cloud, you may want to isolate this VM from others in a different virtual network and temporarily block access from outside.

For more information about incident response in the cloud, we recommend that you read Domain 9 of the Cloud Security Alliance Guidance (8).

主站蜘蛛池模板: 偃师市| 稻城县| 宁海县| 太仆寺旗| 大冶市| 会同县| 大荔县| 墨江| 怀远县| 昌图县| 五原县| 华池县| 图木舒克市| 西贡区| 从化市| 永吉县| 汾阳市| 双流县| 泰宁县| 隆化县| 德保县| 阿鲁科尔沁旗| 安新县| 巩义市| 灵石县| 从江县| 青田县| 平江县| 深圳市| 罗江县| 海淀区| 绿春县| 东丰县| 米脂县| 西贡区| 泗水县| 洛南县| 尚志市| 宜良县| 建平县| 翼城县|