This documentation helps in detecting incident response procedures, provides insights for security monitoring and security updates process
- Alerts for traffic patterns
- Look for inappropriate user behavior or requests
- Isolation od affected systems and revoke access tokens and secrets
- Disable accounts affected
- Detect for malicious code and patch the exploited vulnerability with clearing of logs
- Keep backup for recovery
- Documentation of incident and prevention
- Notfication to regulatory bodies during a security breach
- Look for unauthorised access endpoints
- Increase in user requests
- Failure in Login continuously
- Regularly check for logs and monitor them
- Use tools like Datadog, Splunk, and ELK stack
- Look for admin activities
- Health of system and access to database and authentications details
- Patching of OS and Apps regularly
- Merge dependencies with low risks
- Monitor for anamolies everyday
- Validation of Configuration
- Notification of critical updates to security teams