Chapter 31. Responding to Security Incidents

In this chapter: 
Common Indicators of Security Incidents670
Analyzing a Security Incident676
Conducting Security Investigations680
Implementing Countermeasures to a Security Incident687
Recovering Services After a Security Incident690
Conducting a Security Incident Postmortem690
Best Practices691
Additional Information692

As a network administrator, you must be able to recognize when a security incident is under way. Unfortunately, not all attacks are obvious. Recognizing that the network is under attack early is essential to protecting information or computers that have not yet been compromised. The detection of security incidents centers on investigating events that fall outside of the normal behavior ...

Get Microsoft® Windows® Security Resource Kit, Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.