85
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
4.
Eradication The eradication phase in the incident response process aims to identify, eliminate, and repair the root cause of a cyber incident. The main focus of this phase is to ensure that all malicious components, such as malware, backdoor accounts, and modified system configurations, are completely removed to prevent systems from being vulnerable to recurring attacks.
Key steps in the eradication phase include: a. Identification and Elimination of Malicious Components Conduct a thorough identification of all malicious artifacts such as malware, malicious scripts, web shells, and altered configuration files. This process must cover all systems connected within the network, including those that did not show initial symptoms. Use up-to-date anti- malware and antivirus software with updated signatures, as well as behavior-based detection methods. b. Vulnerability Remediation Perform a vulnerability assessment on the affected systems to identify weaknesses previously exploited by the attacker. Follow up with corrective actions such as patching, configuration hardening, or removal of unnecessary services/components. Mitigation efforts should be prioritized based on risk level (risk-based approach).
Made with FlippingBook Ebook Creator