Remediation

Where the CSIRT will be taking steps to recover and fix devices affected by the incident, the organization will also need to consider how to make good the damage for all the other stakeholders. Customers might need to have their accounts reset, and/or their data recovered. In some cases, particularly where customers' data has been lost or compromised, compensation will need to be considered. This might also be required for unforeseen consequences caused by the issue. 

In 2018, TSB Bank was affected by issues due to a changeover of IT systems. People were unable to pay their bills or make their daily purchases. This all needed to be remediated.

If there is potential that the incident may have exposed other entities (for example, partners), informing them will be vital to ensuring they are able to maintain their own practices. Imagine if a company providing security as a service were to go offline; every organization that they were protecting may now have to enter their own responses, potentially aided by the provider's own CSIRT.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.143.115.131