官术网_书友最值得收藏!

Updating your IR process to include cloud

Ideally, you should have one single incident response process that covers both major scenarios—on-premises and cloud. This means you will need to update your current process to include all relevant information related to the cloud.

Make sure that you review the entire IR life cycle to include cloud-computing-related aspects. For example, during the preparation, you need to update the contact list to include the cloud provider contact information, on-call process, and so on. The same applies to other phases:

  • Detection: Depending on the cloud model that you are using, you want to include the cloud provider solution for detection in order to assist you during the investigation (7).
  • Containment: Revisit the cloud provider capabilities to isolate an incident in case it occurs, which will also vary according to the cloud model that you are using. For example, if you have a compromised VM in the cloud, you may want to isolate this VM from others in a different virtual network and temporarily block access from outside.

For more information about incident response in the cloud, we recommend that you read Domain 9 of the Cloud Security Alliance Guidance (8).

主站蜘蛛池模板: 镇沅| 赞皇县| 通许县| 盘山县| 井冈山市| 湘西| 大洼县| 青冈县| 神池县| 长宁区| 山东省| 宽甸| 浙江省| 哈巴河县| 微山县| 横峰县| 兴业县| 香格里拉县| 偃师市| 乌兰察布市| 镇赉县| 宁河县| 黑山县| 东港市| 玉溪市| 江孜县| 沂水县| 油尖旺区| 白水县| 马公市| 水城县| 定日县| 苏尼特右旗| 九江县| 定边县| 阿克| 威海市| 保康县| 那坡县| 新蔡县| 庆云县|