A brief description of response time, resolution time, and percentage of both of those that should be
Question:
A brief description of response time, resolution time, and percentage of both of those that should be within the agreed times. Define: Response Time - Time between receiving a ticket and an analyst starting work on the ticket Resolution Time - Time between when a ticket is worked by an analyst and when it is either closed as a false finding/authorized activity or forwarded to the IR team.
Incident Response
A brief description of response time, resolution time, and percentage of both of those that should be within the agreed times. Define: Response Time - Time between receiving notification of an incident from the SOC and beginning to investigate and work the incident. Resolution Time - Time between when notified of an incident and when the incident is resolved.
Threat Intelligence
A brief description of response time, resolution time, and percentage of both of those that should be within the agreed times. Define: Response Time - Time between having a threat intelligence report published in a monitored threat feed and the time between when the threat intelligence team reviews the threat report. Resolution Time - Time between when a threat intelligence report is reviewed and when it is resolved. This can be the report being determined as not applicable or when it is forwarded to the SOC as actionable threat intelligence.
Threat Hunting
A brief description of response time, resolution time, and percentage of both of those that should be within the agreed times. Define: Response Time - Time between receiving actionable threat intelligence and starting a threat hunt. Resolution Time - Time between starting a threat hunt and producing final results. This could be no action or could be the creation of an incident.
Incident Response
A brief description of response time, resolution time, and percentage of both of those that should be within the agreed times. Define: Response Time - Time between being notified of an incident and starting triage and full forensics. Resolution Time - Time between starting and completing triage or incident forensics.
Database Systems Design Implementation and Management
ISBN: 978-1285196145
11th edition
Authors: Carlos Coronel, Steven Morris