Indonesian Financial Services Authority
3.2. Detection and Analysis
Use detection tools such as Security Information and Event Management (SIEM) systems Analyze security alert system logs Determine the scope and impact of detected incidents Temporarily block suspicious Internet Protocol (IP) addresses Perform security device checks Utilize Machine Learning (ML) and Artificial Intelligence (AI) technology to improve threat detection capabilities
3.3. Containment
Containment of affected systems Restrict potentially dangerous traffic Temporary access revocation Service termination
3.4. Eradication
Remove all malware or malicious software in infected systems Use anti-malware and antivirus Strengthen system configuration and security settings Repair security systems Testing to ensure malware has been removed
113
Made with FlippingBook. PDF to flipbook with ease