I have a rookie question about incident response.

When the AV flags a virus, what steps should you take to handle the
situation?

I would assume the following would be important to figure out:

   - What the bug is and how it works
   - If any other malware has been planted
   - What the bug actually did to the system, did it steal anything or log
   anything?
   - ??

Looking forward to your responses......

-Craig
_______________________________________________
Pauldotcom mailing list
[email protected]
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

Reply via email to