Data recovery operations can actually begin once containment is achieved. Recovery of critical data systems may be necessary to meet deadlines associated with employees (e.g. payroll) or customers. The important thing to remember is to ensure the system you plan to recover is no longer exposed to the data security threat. Your flexibility in simultaneously executing multiple steps during a data security incident response is directly related to the IRT skills developed during training and practice exercises BEFORE a security attack occurs on your enterprise's data or network.
Depending on the nature of a security attack and your enterprise's ability to quickly identify loss of data and/or computer networks, activities intended to recover corporate data systems might include:
- Reconnecting servers and workstations to the network or data storage devices
- Data and network system restores from tape
- Complete rebuild of data systems
- Replacement of compromised data or reinstallation of applications
- Immediate device hardening
- Install patches
- Change passwords
- Reconfigure physical and logical perimeter devices that protect data
Again, each data security attack is different. With each data recovery response, your teams should get incrementally better at minimizing the amount of data recovery work necessary. This is the purpose of the final step in the incident management process, identifying causes of data security risks and how to manage data security attacks emergencies.