- Cybersecurity:Attack and Defense Strategies
- Yuri Diogenes Erdal Ozkaya
- 139字
- 2021-06-30 19:15:50
Best practices to optimize incident handling
You can't determine what's abnormal if you don't know what's normal. In other words, if a user opens a new incident saying that the server's performance is slow, you must know all the variables before you jump to a conclusion. To know if the server is slow, you must first know what's considered to be a normal speed. This also applies to networks, appliances, and other devices. To mitigate scenarios like this, make sure you have the following in place:
- System profile
- Network profile/baseline
- Log-retention policy
- Clock synchronization across all systems
Based on this, you will be able to establish what's normal across all systems and networks. This will be very useful when an incident occurs and you need to determine what's normal before starting to troubleshoot the issue from a security perspective.
推薦閱讀
- 網絡操作系統:Windows Server 2003管理與應用
- Linux集群和自動化運維
- VMware NSX Cookbook
- 從實踐中學習Kali Linux無線網絡滲透測試
- Hands-On UX Design for Developers
- Linux基礎使用與案例
- Cassandra 3.x High Availability(Second Edition)
- INSTANT Galleria Howto
- Troubleshooting Docker
- bash shell腳本編程經典實例(第2版)
- Docker容器技術與應用
- Linux內核分析及應用
- 鴻蒙入門:HarmonyOS應用開發
- BuddyPress Theme Development
- Responsive Web Design with AngularJS