From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Incident response process

Incident response process

- In this lesson, we're going to discuss the incident response process and its different phases. First though, let's define what an incident is. Now, an incident is an act of violating an explicit or implied security policy. There could be lots of different things that could be categorized as an incident. For example, if I stole your password and tried logging into the computer as you, that would be classified as an incident because it goes against your organization's security policies that state an employee should only log in using their own account credentials. Similarly, if an attacker wanted to install malware in a system, this would also be considered an incident because it breaks the organization's security policies that you've set forth for system integrity. Now, there are lots of different things that could be categorized as an incident, but in this lesson, we want to focus more on what steps or phases there are in conducting an incident response for any kind of incident that…

Contents