官术网_书友最值得收藏!

Best practices to optimize incident handling

You can't determine what's abnormal if you don't know what's normal. In other words, if a user opens a new incident saying that the server's performance is slow, you must know all the variables before you jump to a conclusion. To know if the server is slow, you must first know what's considered to be a normal speed. This also applies to networks, appliances, and other devices. To mitigate scenarios like this, make sure you have the following in place:

  • System profile
  • Network profile/baseline
  • Log-retention policy
  • Clock synchronization across all systems

Based on this, you will be able to establish what's normal across all systems and networks. This will be very useful when an incident occurs and you need to determine what's normal before starting to troubleshoot the issue from a security perspective.

主站蜘蛛池模板: 慈利县| 凉城县| 金坛市| 沅江市| 新巴尔虎右旗| 东兰县| 徐州市| 托克逊县| 迭部县| 罗田县| 乌恰县| 台山市| 乡城县| 福鼎市| 岚皋县| 中方县| 桃园县| 柳河县| 江都市| 三台县| 苗栗县| 延寿县| 布拖县| 威信县| 天祝| 潢川县| 浦县| 道孚县| 甘泉县| 富蕴县| 定西市| 开远市| 上思县| 贞丰县| 新丰县| 偃师市| 本溪市| 星座| 莱芜市| 宣武区| 黄梅县|