Skip to content

Hide Navigation Hide TOC

Function: Response plan establishment (5b155f76-0772-5475-b622-8871d004d94a)

Without fully understanding the business impact and requirements to mitigate and recover, no meaningful response will be provided. As there is a conflict of interest—tracking the attack to gain more intelligence vs. containing the attack to avoid further losses—it is necessary to take all interests into consideration and work out a response plan that is plausible to address the known facts and provide the desired outcome within the required timeframe. As with all plans, it must be considered that whenever new analysis results become available, the new findings need to be reviewed. Indeed, the response plan will usually need to be changed to provide continuous orientation and guidance. But without such plan—unless the response is handled by one small organizational group with little requirement of external interfaces or other entities—the activities might not be carried out effectively or efficiently due to a lack of coordination.

Cluster A Galaxy A Cluster B Galaxy B Level
Function: Response plan establishment (5b155f76-0772-5475-b622-8871d004d94a) FIRST CSIRT Services Framework Service: Mitigation and recovery (d153b816-a767-5bc6-9d78-89f6f49dc11a) FIRST CSIRT Services Framework 1