Cyber Management Course (Ma) – Module 4
Response to an incident, Recovery and Procedures – Action Plan steps
- Initial assessment. To help ensure an appropriate response, the response team should find out:
- how the incident occurred
- which IT and/or OT systems were affected and how
- the extent to which the commercial and/or operational data is affected
- to what extent any threat to IT and OT remains.
- Recover systems and data. Following an initial assessment of the cyber incident, IT and OT systems and data should be cleaned, recovered and restored, so far as is possible, to an operational condition by removing threats from the system and restoring software.
- Investigate the incident. To understand the causes and consequences of a cyber incident, an investigation should be undertaken by the company, with support from an external expert, if appropriate. The information from an investigation will play a significant role in preventing a potential recurrence. Investigations into cyber incidents are covered in section 7.3.
- Prevent a re-occurrence. Considering the outcome of the investigation mentioned above, actions to address any inadequacies in technical and/or procedural protection measures should be considered, in accordance with the company procedures for implementation of corrective action.