Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add "initiate incident response" as a decision outcome? #542

Open
ahouseholder opened this issue Mar 13, 2024 · 1 comment
Open

Add "initiate incident response" as a decision outcome? #542

ahouseholder opened this issue Mar 13, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@ahouseholder
Copy link
Contributor

ahouseholder commented Mar 13, 2024

Based on a comment from @j---, it's possible that a response decision could also involve an "inititate incident response". For example, if you're already behind on fixing something that's open exposure, actively exploited, and automatable, you might want to default to assuming you're already hit and so in addition to patching fast, you want to also investigate whether you're already hit.

@ahouseholder ahouseholder added the enhancement New feature or request label Mar 13, 2024
@sei-vsarvepalli
Copy link
Contributor

Justin from CISA Red Team pointed this out at the meeting on March 13, 2024.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants