Identification

13th January 2020 | Cybrary Identification


Identification refers to the first step in the incident response process where an organization determines whether they have been breached or not.  Security professionals will seek indicators of compromise while in this step of incident response.  They will attempt to find damage that’s been done to computer systems or a network, or evidence that data has been copied and removed from its secure locations within an environment or business system.  Not every security breach yielded damage to networks or computers, they often amount to the theft of intellectual property or critical data such as financial records, health records or other Non-Public Personal Information (NPPI).

The ultimate purpose of Identification is to determine if an incident has occurred and whether to invoke an Incident Handling process or stand down the resources that are being marshalled to fight a potential breach.

Related Terms: Containment, Eradication, Recovery, Revision, Incident Response

To learn more about Incident Response, watch this short video:

CyberHoot does have some other resources available for your use. Below are links to all of our resources, feel free to check them out whenever you like: 

Note: If you’d like to subscribe to our newsletter, visit any link above (besides infographics) and enter your email address on the right-hand side of the page, and click ‘Send Me Newsletters’.

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

Microsoft Integrates Passkeys into Windows: is this the start of a Passwordless Future?

Microsoft Integrates Passkeys into Windows: is this the start of a Passwordless Future?

Let’s be honest, who hasn’t reset a password at least once this month? For decades, passwords have been our...

Read more
When You Become the Hacker: How Modern Attacks Trick You Into Hacking Yourself

When You Become the Hacker: How Modern Attacks Trick You Into Hacking Yourself

In a shift away from the usual “hack-meets-victim” narrative, a new kind of cyber-assault is emerging. One...

Read more
Domain Takedowns: How to Remove Fraudulent and Typo-squatted Domains and Websites

Domain Takedowns: How to Remove Fraudulent and Typo-squatted Domains and Websites

In cybersecurity, not all attacks happen through fancy malware or zero-day exploits. Some of the most effective...

Read more