Cybersecurity Guidelines for FSTI Providers
5.4. Eradication
The eradication or cleaning phase in incident response is an effort focusing on removing the root cause of the occurred security event and preventing similar future events. At this phase, incident response team perform several key actions, among others:
1.
Identify and remove malicious malware of software from the affected system. Use anti-malware and antivirus and ensure all systems are scanned, not just those initially affected.
2.
Repair security vulnerabilities that were exploited by attackers to prevent similar events. Repair according to the risk level of exposed vulnerabilities.
3.
Strengthen system configuration and security settings to enhance overall security posture.
4.
Run a series of testing to ensure the malware has been completely removed and systems are restored to their secure state before reconnecting them to the network.
58
Made with FlippingBook. PDF to flipbook with ease