| Rogue server or service verified? |
Determine whether a connection with a rogue server or
service has been verified on your network. In the task,
select Yes or
No in
Outcome. |
If you select Yes, the following
two tasks are executed in parallel:
- Identify impacted
system(s)
- Potential data loss?
If you select No, the flow
ends. |
| Identify impacted system(s) |
Determine the systems impacted by contact with the rogue
server or service. |
When this task is complete, the Update
system(s) - Remove rogue connections task is
executed. |
| Potential data loss? |
Determine whether the connection with the rogue server or
service caused potential data loss. In the task, select
Yes or
No in
Outcome. |
If you select Yes, the
Create potential data loss
incident task is executed. If you select
No, the Update
system(s) - Remove rogue connections
task is executed. |
| Create potential data loss incident |
Perform the steps necessary to create a security incident
for the potential data loss. |
When this task is complete, the Update
system(s) - Remove rogue connections task is
executed. |
| Update system(s) - Remove rogue connections |
Perform the steps necessary to remove the rogue
connections. |
When this task is complete, the Set state to
review task is executed. |
| Set state to review |
No action required. |
The State of the security incident
is changed automatically to Review,
and the Lessons learned meeting task
is executed. |
| Lessons learned meeting |
Conduct a lessons learned meeting to triage the work
performed for this rogue server or service incident.
Update the State field in the
task as appropriate. |
When this task is complete, the flow ends. |