Following a breach where the risk has been isolated and forensic processes have been performed, which of the following should be done NEXT?
Following a breach where the risk has been isolated and forensic processes have been performed, which of the following should be done NEXT?
Following a breach where the risk has been isolated and forensic processes have been performed, it is crucial to ensure the server is rebuilt securely. Rebuilding the server with relevant patches from the original media helps in addressing any potential vulnerabilities that may have been exploited during the breach. Simply restoring from a backup could reintroduce vulnerabilities if the backup does not have the latest security patches.
ISACA has the same question#37 in their Q&A.
Backups could be contaminated