Security, Resilience, and Incident Response Strategies
Synopsis
Although preventive security controls (e.g., malware protection, firewalls, strong authentication) attempt to ensure confidentiality, integrity, and availability of information systems, no system can be fully secured. Data breaches, denial of service, and malware infections will continue to occur. The expectation is not that organizations will be ever free from security incidents, but that they will be sufficiently resilient to withstand them without suffering unacceptable damage. Striking the correct balance between security and resilience is essential. Resilience by itself, however, is insufficient. Organizations, in particular, must also be able to detect incidents accurately and quickly so that timely and effective remedial actions can be taken. An effective incident response capability complements resilient systems by enabling organizations to recover quickly and reduce the damaging impact of security breaches.










