ခဏလေး ဒီလိုပဲ စဉ်းစားကြည့်
Incident Response lifecycle ရဲ့ phase အဓိက ၅ ခု ရှိပါတယ် — Preparation (IR plan/tool ကို ကြိုတင် ပြင်ဆင်ခြင်း), Identification (incident ဖြစ်နေလား စစ်ဆေးခြင်း), Containment (damage ကို ကန့်သတ်ခြင်း, ဥပမာ - infected machine ကို network ကနေ ချက်ချင်း ဖြုတ်ခြင်း), Eradication (root cause ကို ဖယ်ရှားခြင်း), Recovery (system ကို ပုံမှန်အခြေအနေ ပြန်ရောက်စေခြင်း) — ပြီးရင် Lessons Learned (root cause documentation, ထပ်မဖြစ်ရအောင် improvement) ကို ဆက်လုပ်ရပါတယ်.
လက်တွေ့ scenario နဲ့ ချိတ်ကြည့်မယ်
Company တစ်ခုမှာ ransomware infection detect ရင် — Containment အနေနဲ့ infected machine ကို network ကနေ ချက်ချင်း disconnect (spread ကို ကန့်သတ်ဖို့), Identification/Eradication အနေနဲ့ malware ရဲ့ entry point (phishing email? vulnerability?) ကို ရှာဖွေ, Recovery အနေနဲ့ clean backup ကနေ system ကို restore, Lessons Learned အနေနဲ့ 'ဘယ်လို ဒီလို ဖြစ်ခဲ့လဲ, နောက်တစ်ခါ ဘယ်လို ကာကွယ်မလဲ' ဆိုတဲ့ report ရေးရပါတယ် — ဒီ order (Containment ကို Eradication ထက် အရင်) က အရေးကြီးပါတယ်, damage spread ကို အရင်ရပ်ရမှာမို့.
အတူတူ ကြည့်မယ်
Incident Response Lifecycle
=============================
1. Preparation — IR plan, tools, contacts ready BEFORE an incident
2. Identification — confirm: is this actually an incident?
3. Containment — stop the spread (isolate affected systems)
4. Eradication — remove the root cause (malware, backdoor)
5. Recovery — restore systems to normal operation
6. Lessons Learned — document root cause, improve for next timeIR lifecycle ရဲ့ ၆ ဆင့်ကို sequence အတိုင်း ရှင်းပြနိုင်မည်။၅ မိနစ် စမ်းကြည့်
'Company laptop တစ်လုံးမှာ ransomware ဖြစ်နေတယ်' ဆိုတဲ့ scenario ကို IR lifecycle ၆ ဆင့်အတိုင်း (Preparation ကလွဲပြီး) response step ကို ကိုယ်တိုင် ရေးဆွဲကြည့်ပါ။
သတိလေးတစ်ချက်
Real incident response ကို practice/simulation မဟုတ်ဘဲ တကယ့် production environment မှာ လုပ်ဆောင်တဲ့အခါ, IR plan/authorization ရှိတဲ့ team member ကသာ lead လုပ်သင့်ပါတယ် — unauthorized 'helpful' action (evidence ဖျက်မိခြင်း, log ဖျက်မိခြင်း) က forensic investigation ကို ပိုဒုက္ခရောက်စေနိုင်ပါတယ်.