SANS Site Network
Current Site
Security Training
Choose a different site
Help
Security Certification
Cyber Security Graduate School
Internet Storm Center
Security Awareness Training
Computer Forensics
Penetration Testing
IT Audit
Software Security
Secure Access / Login
Find Training
Search For Training
Upcoming Events
Course List
NetWars
Ways To Train
Without Travel
Training Curricula »
Security
Management
Forensics
Secure Software Development
Penetration Testing
System Administration
Incident Handling
Intrusion Analysis
Audit
Legal
Cyber Guardian
Group Discounts
Calendars
Live Training
Search For Training
Upcoming Events
Summits
Community Events
Mentor
OnSite
Work Study
COINS
Online Training
Search For Training
CyberCon
vLive
OnDemand
Simulcast »
Event
Custom
Security Awareness
SelfStudy
Programs
Voucher Credit
Cyber Guardian
Cyber Ranges
Hacker Guard
Cybersecurity Innovation Awards
Enterprise Solutions
CISSP Get Certified
DoD 8570
Resources
Reading Room
Webcasts
Newsletters
Blogs
Top 25 Programming Errors
Top 20 Critical Controls
Security Policy Project
From Vendors
Additional Resources
Vendor
Overview
Sponsorship
Demographics
Events
Contact
About
About SANS
Why SANS?
Instructors
Contact SANS
SANS FAQ
Link to SANS
Press Room
PGP Key
PGP Key - Local Copy
Intrusion Detection FAQ: If I suspect a system is compromised what should I do?
More than 90 experienced incident handlers agreed on the following steps:
Remain calm; don't hurry.
Notify your organization's management.
Provide a game plan (with options if possible).
Apply need-to-know.
Use out-of-band communications; avoid email and other network-based communications channels.
Take good notes, good enough to serve as evidence in a court of law.
Contain the problem; pull the network cable.
Back up the system(s), and collect evidence.
Eradicate the problem and get back in business.
Lessons learned, apply what you have learned.
< Previous Question
|
Back to Intrusion Detection FAQ Home
|
Next Question >
Check Them Out!
SANS Security West 2013
Security Awareness Training
Top Cyber Security Risks
SANS Reading Room
Career Roadmap
Storm Center
WhatWorks™
Newsletters
I think this course changed my life.
-James Welcher, LBNL