preview

Section Five Performance Measures

Better Essays

Section Five – Performance Measures 5.1 Introduction This section covers the performance measures that are used as a standard to help define a successful incident response. The five main indicators used are: the detection time, recovery time, recovery effectiveness, cost, and lessons learned. The recovery process should be prompt, organized, and justifiable. 5.1.1 Detection Time Detection time is how long until an incident was reported to the IR team. Widgets “R” Us’ employees should always be vigilant to keep detection time to a minimum. The following chart gives an approximate maximum length of time that can pass before an incident should have been detected and reported: Incident Type Maximum Detection Time Outage of Critical Business …show more content…

No shortcuts or temporary measures were taken in the recovery process C. Objects recovered were what was necessary 5.1.4 Cost The cost of recovery should be balanced between providing the best recovery efforts while staying within operational budgets. Any extra expenses should be justifiable. IR members should ask themselves the following: • Can we justify the expense for the steps taken during recovery? • Would purchasing better equipment have saved us time or protected us from this incident? • If so, how would it have done so? • Are there any changes we can make to reduce costs without negatively impacting recovery efforts? The answers to these questions should be included in the after-action review. 5.1.5 Lessons Learned After the conclusion of the incidents recovery, the IR team should have learned from their recovery efforts. IR team members should ask themselves the following: • Did we detect the incident in a reasonable amount of time? • If not, what hindered our ability to detect the incident effectively? • How can we further improve our detection methods? • Was our recovery method prompt, organized, and justifiable? • If not, what can we change to achieve this? • How can we further improve our recovery …show more content…

(2010a). Incident response plan. Retrieved from https://cdn.ttgtmedia.com/searchDisasterRecovery/downloads/SearchDisasterRecovery_Inciden t_Response_Plan_Template.doc Tech Target. (2010b). Incident response plan. Retrieved from https://cdn.ttgtmedia.com/searchDisasterRecovery/downloads/SearchDisasterRecovery_Inciden t_Response_Plan_Template.doc (32, 36) Whitman, M. E., Mattord, H. J., & Green, A. (2014). Principles of incident response & disaster recovery. Boston, MA: Course Technology Cengage Learning.

Get Access