Download Publication
Who it's for:
- All cloud customers
- Cloud service providers who need a clear framework for sharing incident response practices with customers
Cloud Incident Response Framework
Release Date: 05/04/2021
Working Group: Cloud Incident Response
This framework created by the Cloud Incident Response Working Group serves as a go-to guide for cloud customers to effectively prepare for and manage cloud incidents. It explains how to assess an organization’s security requirements and then opt for the appropriate level of incident protection. Cloud customers will learn how to negotiate with cloud service providers, select security capabilities that are made-to-measure, and divide security responsibilities.
Key Takeaways:
- How to effectively manage cloud incidents through the entire lifecycle of a disruptive event, including:
- Preparation
- Detection and analysis
- Containment, eradication, and recovery
- Post-mortem
- How to coordinate and share information with stakeholders and other organizations
Download this Resource
Acknowledgements
Alex Siow
Soon Tein Lim
Ashish Vashishtha
Security Compliance Leader
Analytical, results-oriented IS/IT Audit, Governance, Risk, and Compliance (GRC) leader over 19 years of experience managing enterprise-wide IT/IS security risk approach for large healthcare and IT services organizations. Passionate design thinker with an ability to harness innovation by facilitating collaboration to develop enterprise-wide security risk assessments (onsite as well as remote) for high-risk Third-Parties leveraging NIST 800-...
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC
Since 2012, Michael Roza has been a pivotal member of the Cloud Security Alliance (CSA) family. He has contributed to over 125 projects, as a Lead Author or Author/Contributor and many more as a Reviewer/Editor.
Michael's extensive contributions encompass critical areas including Artificial Intelligence, Zero Trust/Software Defined Perimeter, Internet of Things, Top Threats, Cloud Control Matrix, DevSecOps, and Key Management. His lea...
Dennis Holstein
Haojie Zhuang
Larry Marks
Oscar Monge Espana
Nirenj George
Fadi Sodah
Abhishek Pradhan
Saan Vandendriessche
Tanner Jamison
Bowen Close
David Cowen
Ekta Mishra
Membership Director & Country Manager (India), CSA APAC
Ashish Kurmi
Christopher Hughes
Karen Gispanski
Vani Murthy
Sr. Information Security Compliance Advisor, Akamai Technologies
Vani has 20+ years of IT experience in the areas such as Security, Risk, Compliance, Cloud services (IaaS/PaaS/SaaS) architecture
David Chong
Sandeep Singh
Dr. Ricci Ieong
Dr Ricci Ieong is the principal consultant of eWalker Consulting (HK) Ltd. and has over 20 years of industry experience in information technology, as well as more than 17 years of experience in IT security, where he specializes in security risk assessment, IT audit, penetration testing, and computer forensics investigation. He is the former vice chairman of professional development of Cloud CSA (HK & Macau Chapter) and has serve...
Aristide Bouix
Chelsea Joyce
Interested in helping develop research with CSA?
Related Certificates & Training
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more