Imagine a circular cycle divided into five stages, each with its respective color and icon:
Detection (Light green, magnifying glass icon): The initial stage, where a security incident is identified and reported.
Containment (Yellow, shield icon): The stage of immediate actions to contain the incident, such as isolating systems and blocking access.
Investigation (Light blue, magnifying glass icon): The stage of in-depth analysis of the incident, seeking its cause, impact, and scope.
Eradication (Red, fire icon): The stage of eliminating the cause of the incident, such as removing malware and patching vulnerabilities.
Recovery (Dark green, upward arrow icon): The stage of restoring systems and services affected by the incident, such as recovering backups and reconfiguring systems.
想象一个圆形循环,分为五个阶段,每个阶段都有各自的颜色和图标:
检测 (浅绿色,放大镜图标): 初始阶段,识别并报告安全事件。
遏制 (黄色,屏蔽图标): 立即采取措施以遏制事件的阶段,例如隔离系统和阻止访问。
调查 (浅蓝色,放大镜图标): 深入分析事件的阶段