你這流程怪怪的,是不是沒有確實執行
恩... 來看一下美國聯邦政府及美國公共電力協會的IR Playbooks怎麼做
這是 2021年 Cybersecurity and Infrastructure Security Agency (CISA)基於 Executive Order 14028 行政命令所制定的Playbook
該流程是以 National Institute of Standards and Technology (NIST) Special Publication (SP) 800-61 Rev. 2,5 做展開
有五個階段跟一個外部協助,有用顏色分別,依照這流程執行清楚多了
https://www.publicpower.org/system/files/documents/Public-Power-Cyber-Incident-Response-Playbook.pdf
Federal Government Cybersecurity Incident and Vulnerability Response Playbooks
https://www.cisa.gov/sites/default/files/publications/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
Public-Power-Cyber-Incident-Response-Playbook
https://www.publicpower.org/system/files/documents/Public-Power-Cyber-Incident-Response-Playbook.pdf
SP 800-61 Rev. 2
https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final