up

2020-01-28- whatwhat

Move reflections from CPA3 to content notes.

IR is what you do while an event is happening. How to cope with security events.

NIST IR Framework

IR Policy

Plan and policy are related but not the same

CSIRT := Computer Security Incident Response Team

IR Response Strategy

IR Plan

It appears the case study is a mirror of what we will need to do on our own

Containment

Eradication

Reflection