情報セキュリティ チームは、脅威アクターがアプリケーション内で新たに発表された重大な脆弱性を悪用していることを確認しました。最初に実行する必要があるのは次のうちどれですか。
正解:C
According to the NIST SP 800-61 Computer Security Incident Handling Guide1, the first step in responding to a cybersecurity incident is to invoke the incident response plan (IRP), which is a written document that defines the roles, responsibilities, and procedures for dealing with a confirmed or suspected security breach1. The IRP helps the organization to prepare for, detect, analyze, contain, eradicate, recover from, and learn from incidents1. Invoking the IRP ensures that the right personnel and resources are mobilized to effectively deal with the threat and minimize the impact.
References = 1: NIST SP 800-61: 1. Introduction1