IR

Detection & response

Catching an incident early, and what to do in the first hours after.

15 terms

What catches an incident early, and what a firm actually does in the first hours and days after one starts.

Showing 15 of 15
Business continuity plan (BCP) A plan for keeping critical business functions running during a disruption. Digital forensics A structured investigation after an incident to determine what happened. Disaster recovery plan (DRP) The technical plan for restoring IT systems after a major disruption. Endpoint & extended detection and response (EDR/XDR) Watches devices for malicious behavior; XDR extends that across more sources. Incident response plan (IRP) A written, rehearsed plan for the first hours and days of an incident. Indicator of compromise (IOC) Evidence a system has already been breached. Managed detection and response (MDR) An outsourced service that actively monitors and responds to threats for you. Penetration testing An authorized simulated attack to find exploitable weaknesses. Recovery point objective (RPO) The maximum acceptable data loss, measured in time. Recovery time objective (RTO) The maximum acceptable time to get a system back up after a disruption. Security information and event management (SIEM) Collects logs across systems and correlates them to surface suspicious activity. Security operations center (SOC) The team that watches security alerts and responds around the clock. Tabletop exercise A practice run of an incident response plan, without touching live systems. Threat intelligence Information about active attackers used to anticipate and recognize them. Vulnerability scanning Automated, regular scanning to find known weaknesses before attackers do.