04 - Respond and Recover Functions
respond-and-recover-functions', 'appsec', 'security', 'compliance']β
04 - Respond and Recover Functions
RESPOND (RS)β
When a breach occurs, the Respond function focuses on containing the impact and coordinating the organizational response.
Incident Management (RS.MA)β
- Playbooks: Develop and maintain incident response playbooks for common scenarios (Ransomware, Data Breach, DDoS).
- Containment: Isolate compromised systems rapidly (e.g., disconnecting a VM from the network, disabling compromised IAM roles).
- Eradication: Remove the threat actor's access and malware from the environment.
Communications (RS.CO)β
- Internal: Notify stakeholders, legal teams, and executives.
- External: Coordinate with PR, regulatory bodies, and law enforcement as required by law.
RECOVER (RC)β
Recovery is about resilienceβrestoring capabilities or services that were impaired due to a cybersecurity event.
Recovery Plan Execution (RC.RP)β
- Backups: Ensure immutable, offsite backups are available and tested.
- RTO/RPO: Meet defined Recovery Time Objectives and Recovery Point Objectives.
Continual Improvement (RC.CI)β
- Lessons Learned: Conduct blameless post-incident reviews (PIRs).
- Framework Updates: Update the Target Profile, risk assessments, and playbooks based on lessons learned.
[!IMPORTANT] The effectiveness of Respond and Recover relies entirely on preparation. Conduct regular tabletop exercises simulating ransomware or cloud compromises to test your RC.RP and RS.MA outcomes.