{"id":8925,"date":"2025-09-23T11:39:53","date_gmt":"2025-09-23T02:39:53","guid":{"rendered":"https:\/\/www.somansa.com\/?page_id=8925"},"modified":"2026-07-06T13:27:53","modified_gmt":"2026-07-06T04:27:53","slug":"edr_av_irp","status":"publish","type":"page","link":"http:\/\/somansa.presscat.kr\/en\/edr_av_irp\/","title":{"rendered":"Somansa Privacy-i EDR\/Antivirus Incident Response Plan"},"content":{"rendered":"<h1 style=\"padding-left: 40px;\">\u00a0<\/h1>\r\n<h1 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 24pt;\">Somansa Privacy-i EDR\/Antivirus <\/span><\/h1>\r\n<h1 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 24pt;\">Incident Response Plan<\/span><\/h1>\r\n<p>&nbsp;<\/p>\r\n<h2 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Introduction and Purpose<\/span><\/h2>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">This document outlines the procedures for incident response involving Somansa\u2019s Privacy-i EDR, a next-generation endpoint detection and response solution. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Privacy-i EDR monitors endpoints in real time for security threats, automatically blocking malware and suspicious behavior on Windows 10\/11 desktops<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=,and%20prevention%20using%20behavioral%20engines\">[1]<\/a><a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=3.%20Built,encryption%20or%20abnormal%20behavior%20occurs\">[2]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The purpose of this plan is to ensure that any security incident detected by Privacy-i EDR is swiftly <strong>detected<\/strong>, properly <strong>reported<\/strong>, <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">and effectively <strong>responded to<\/strong> and <strong>remediated<\/strong>, minimizing damage and meeting compliance requirements. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">It defines roles, communication channels, and step-by-step response actions so that security teams can react quickly and consistently to endpoint security incidents.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"color: #808080;\"><em><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Scope:<\/strong> This plan applies to all security incidents on company endpoints (desktops and laptops) that are identified by Somansa Privacy-i EDR. <\/span><\/em><\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"color: #808080;\"><em><span style=\"font-family: helvetica, arial, sans-serif;\">It covers malware infections (including ransomware and fileless attacks), unauthorized or suspicious activities detected by the EDR agent, <\/span><\/em><\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"color: #808080;\"><em><span style=\"font-family: helvetica, arial, sans-serif;\">and other endpoint threats. Incidents unrelated to endpoints or not detected by the EDR are outside the scope of this document.<\/span><\/em><\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<h2 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Roles and Responsibilities<\/span><\/h2>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Security Operations Center (SOC) \/ EDR Monitoring Team:<\/strong> The SOC is responsible for 24\/7 monitoring of Privacy-i EDR alerts and logs.<\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">When Privacy-i EDR detects a threat, it generates an alert in the central management console. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">SOC analysts (Tier 1) investigate these alerts and determine if they represent a true security incident. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">They are the first line of response, tasked with initial incident <strong>identification<\/strong> and classification.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Incident Response Team (CSIRT):<\/strong> The dedicated incident response team (Tier 2\/Tier 3 or CSIRT) takes over confirmed incidents from SOC analysts.<\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">This team includes incident responders and forensic analysts who will contain and eradicate threats. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">A designated <strong>Incident Manager<\/strong> will coordinate the response, ensure communication among stakeholders, and track the incident to closure. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The Incident Response Team works closely with IT support for remediation actions like system isolation or restoration.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>IT Support\/Desktop Team:<\/strong> Provides support in containment and recovery steps. For example, they assist in disconnecting an affected machine from the network if needed, <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">deploying patches, or re-imaging systems that were severely compromised. They work under the guidance of the Incident Response Team during an incident.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Management and Compliance:<\/strong> The IT Security Manager or CISO is informed of high-severity incidents. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">They handle any necessary escalation to executive management and oversee external communications. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">They ensure that any reporting obligations (to customers, regulators, etc.) are met after major incidents. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Management also approves and supports any major remediation steps that impact operations.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Somansa Support (Vendor):<\/strong> Somansa\u2019s technical support and security response resources are available if specialized assistance is needed. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Privacy-i EDR is backed by Somansa\u2019s malware analysis and security response centers<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=3,vulnerability%20research%2C%20and%20security%20response\">[3]<\/a>, meaning expert help can be sought for complex malware analysis or product-related issues.<\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"> Somansa provides product support via email and phone during business hours (8&#215;5) as part of the maintenance agreement<a href=\"http:\/\/somansa.presscat.kr\/en\/newsevent\/somansa-privacy-i-saas-endpoint-dlp\/#:~:text=Support%20is%20included%20and%20is,from%20a%20competent%20DLP%20product\">[4]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The Incident Manager may contact Somansa support (e.g., via support@somansa.com or the support hotline) <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">if the team encounters an unknown threat that requires vendor expertise or if there are questions on EDR functionality during an incident.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Communication and Contact Points:<\/strong> An up-to-date contact list is maintained with on-call personnel. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">For any suspected <strong>critical<\/strong> incident, the SOC immediately notifies the Incident Response Team lead (by phone and ticketing system) and the Security Manager. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The Incident Manager will keep management and affected business unit leaders informed at regular intervals. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">If required by policy or law, the CISO will handle communication with external parties (e.g. customers, regulators, law enforcement). <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Internally, incident status updates will be communicated through the incident tracking system and email updates.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<h2 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Incident Detection and Reporting<\/span><\/h2>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Privacy-i EDR agents continuously monitor endpoint activities and use both signature-based and behavior-based detection engines to identify threats<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=Somansa%E2%80%99s%20Privacy,the%20best%20among%20domestic%20products\">[5]<\/a><a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=%5BKey%20Features%5D%201.%20Dual,day%2C%20polymorphic%2C%20and%20fileless%20attacks\">[6]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">When a potential security incident is detected on an endpoint (such as malware execution, suspicious script, or unauthorized access attempt), <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">the agent will <strong>immediately block or quarantine<\/strong> the malicious activity in real time<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=3.%20Built,encryption%20or%20abnormal%20behavior%20occurs\">[2]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">For example, if ransomware behavior is detected, Privacy-i EDR\u2019s behavior engine will stop the encryption process and isolate the offending process. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">It also captures relevant data (process details, file paths, network connections) about the event.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Alerting:<\/strong> The EDR agent reports the incident to the centralized EDR management console (EDR server). <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">An alert is generated containing details of the threat (affected host, type of threat, severity, timestamps, indicators). <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The console may also categorize the alert according to the MITRE ATT&amp;CK framework tactics and techniques<a href=\"https:\/\/m.boannews.com\/html\/detail.html?idx=112002&amp;kind=#:~:text=%E2%80%98Privacy,%EC%8B%9D%EB%B3%84%2C%20%EC%A0%81%EC%9A%A9%2C%20%EB%B0%B0%ED%8F%AC%ED%95%A0%20%EC%88%98%20%EC%9E%88%EB%8B%A4\">[7]<\/a>, giving analysts insight into the nature of the attack. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The Privacy-i EDR system provides a dashboard with real-time status indicators (green\/yellow\/orange\/red) to reflect the environment\u2019s security status<a href=\"http:\/\/somansa.presscat.kr\/en\/newsevent\/somansa-privacy-i-saas-endpoint-dlp\/#:~:text=were%20quite%20pleased%20to%20see,questions%20about%20your%20system%E2%80%99s%20status\">[8]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">When an incident occurs, it would be reflected as a high-severity event (e.g., red status) on the dashboard, ensuring it gains immediate attention.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Reporting Workflow:<\/strong> Upon an alert, the SOC analyst on duty reviews the Privacy-i EDR console for details. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The product\u2019s incident management features allow the analyst to annotate the alert, assign it a severity, and initiate an incident ticket. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Privacy-i includes an incident workflow capability \u2013 administrators can make decisions or <strong>delegate incidents to appropriate personnel as part of a workflow<\/strong><a href=\"http:\/\/somansa.presscat.kr\/en\/newsevent\/somansa-privacy-i-saas-endpoint-dlp\/#:~:text=The%20system%20has%20a%20good,to%20the%20director%20of%20HR\">[9]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Using this feature, if the incident appears to involve sensitive data (for example, a data leakage attempt alongside malware), <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">the analyst might involve a data protection officer or HR (for an internal violation) by delegating that incident in the system<a href=\"http:\/\/somansa.presscat.kr\/en\/newsevent\/somansa-privacy-i-saas-endpoint-dlp\/#:~:text=The%20system%20has%20a%20good,to%20the%20director%20of%20HR\">[9]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">In general, the SOC will create a formal incident record in the Incident Response tracking system, which includes all relevant details from the EDR alert.<\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The incident is then classified (e.g., Malware Infection, Ransomware, Unauthorized Access, etc.)<\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"> and given an initial severity rating (Critical\/High\/Medium\/Low) based on its potential impact. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">If the incident is Critical or High, the SOC escalates immediately to the Incident Response Team (by direct phone call to on-call responders, in addition to the ticket). <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">For lower severity incidents (e.g., a contained malware that was successfully quarantined by the EDR and caused no damage), <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">the SOC may handle the containment and documentation, and just notify the Incident Response Team in a daily report.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<h2 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Incident Response Procedures<\/span><\/h2>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Once an incident is confirmed and reported, the Incident Response Team will proceed through the following phases in line with industry best practices<a href=\"https:\/\/www.wiz.io\/academy\/incident-response-fast-track-guide#:~:text=Incident%20response%20is%20a%20strategic,from%20threats%20quickly%20and%20efficiently\">[10]<\/a><a href=\"https:\/\/www.wiz.io\/academy\/incident-response-fast-track-guide#:~:text=The%20incident%20response%20plan%20expands,outline%20plans%20on%20how%20to\">[11]<\/a>:<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\"><strong>1. Identification &amp; Analysis:<\/strong> The Incident Response Team verifies the incident details. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">They collect as much information as possible from Privacy-i EDR\u2019s logs and console: which files or processes were flagged, what actions the malware attempted, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">and on which endpoints. Privacy-i EDR\u2019s ability to record endpoint behaviors and provide a <strong>timeline or process tree of the attack<\/strong> (including cause-effect analysis) helps <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">responders determine the scope and root cause of the incident<a href=\"https:\/\/m.boannews.com\/html\/detail.html?idx=112002&amp;kind=#:~:text=%EC%86%8C%EB%A7%8C%EC%82%AC%2C%20%EC%A0%95%EC%A0%81%C2%B7%EB%8F%99%EC%A0%81%202%EB%8B%A8%EA%B3%84%20%EB%B6%84%EC%84%9D%20%ED%86%B5%ED%95%9C,%EC%A4%91%EC%9D%B8%20%EC%95%88%ED%8B%B0%EB%B0%94%EC%9D%B4%EB%9F%AC%EC%8A%A4%20%EC%86%94%EB%A3%A8%EC%85%98%20%EB%8C%80%EC%B2%B4%EB%8F%84%20%EA%B0%80%EB%8A%A5%ED%95%98%EB%8B%A4\">[12]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The team correlates this with other data (SIEM logs, network alerts) to assess whether the threat has spread to other systems. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">If multiple endpoints show similar alerts, the team identifies all affected systems. This analysis phase leverages Privacy-i\u2019s built-in forensic data; <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">for example, <strong>log and process data are available for search and investigation<\/strong> via the EDR console, allowing rapid root cause analysis<a href=\"https:\/\/www.sentinelone.com\/cybersecurity-101\/endpoint-security\/edr-solutions\/#:~:text=Endpoint%20Detection%20and%20Response%20solutions,endpoint%20protection%20and%20response%20features\">[13]<\/a><a href=\"https:\/\/www.sentinelone.com\/cybersecurity-101\/endpoint-security\/edr-solutions\/#:~:text=ransomware,to%20previous%20and%20safer%20states\">[14]. <\/a><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\">If needed, the team may retrieve copies of suspicious files from the affected endpoint (Privacy-i EDR will have quarantined malicious files, making them available for analysis).<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\">They may also consult threat intelligence (Privacy-i EDR receives threat info from Microsoft\u2019s security feeds and Somansa\u2019s own Threat Intelligence (TI) services<a style=\"font-family: helvetica, arial, sans-serif;\" href=\"http:\/\/somansa.presscat.kr\/en\/product\/edrsummary\/#:~:text=,Virus%20Initiative%20by%20Microsoft\">[15]<\/a><a style=\"font-family: helvetica, arial, sans-serif;\" href=\"http:\/\/somansa.presscat.kr\/en\/product\/edrsummary\/#:~:text=Ransomware%20activity%20is%20saved%20and,TI%29%20systems\">[16]<\/a><span style=\"font-family: helvetica, arial, sans-serif;\">) <\/span><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">to identify the malware family or attack indicators. Based on analysis, the team updates the incident classification and refines the response strategy.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\"><strong>2. Containment:<\/strong> In this phase, the priority is to limit the damage. Privacy-i EDR has <strong>automated containment capabilities<\/strong>,<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\"> such as quarantining malicious files and terminating malicious processes immediately when detected<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=3.%20Built,encryption%20or%20abnormal%20behavior%20occurs\">[2]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">This automatic first response often halts the attack on the initial endpoint. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The Incident Response Team assesses if additional containment is needed. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">For example, they may isolate the affected host from the network (either by instructing IT to disconnect it or using any network isolation feature if available in the EDR agent). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Some EDR solutions allow remote host isolation; if Privacy-i EDR supports it, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">the team will trigger that for a compromised machine (to prevent an attacker from communicating out or spreading malware). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">All containment actions (quarantine, kill process, network isolation, etc.) are logged.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">During containment, the team also might apply temporary measures enterprise-wide if needed. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">For instance, if a new malware strain is spreading, they could use Privacy-i EDR to push an updated block rule or IOC (Indicator of Compromise) across all agents. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Privacy-i EDR facilitates this by sharing threat intelligence and newly discovered IOCs with all endpoint agents in real time<a href=\"http:\/\/somansa.presscat.kr\/en\/product\/edrsummary\/#:~:text=Ransomware%20activity%20is%20saved%20and,TI%29%20systems\">[16]<\/a> \u2013 meaning once one agent detects a new threat, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">all other agents can <strong>immediately block the same threat<\/strong>, reducing the chance of lateral spread. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">This <strong>simultaneous response across endpoints and the network<\/strong> is part of the solution\u2019s design<a href=\"http:\/\/somansa.presscat.kr\/en\/product\/edrsummary\/#:~:text=Ransomware%20activity%20is%20saved%20and,TI%29%20systems\">[16]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">If the incident involves a compromised user account or suspicious network traffic, containment might also include disabling accounts or blocking IPs at the firewall, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">but those steps are handled by the broader security team (with SOC coordination).<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Communication during containment: The Incident Manager provides updates to management if it\u2019s a severe incident, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">especially if multiple endpoints or sensitive data are involved. Users of affected PCs may be instructed to stop using them temporarily.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>3. Eradication:<\/strong> After containing the immediate threat, the team focuses on removing the threat from all affected systems. <\/span><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Privacy-i EDR\u2019s dual-engine approach not only detects threats but can also assist in removal.<\/span><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: helvetica, arial, sans-serif;\"> All malicious files identified are already quarantined by the agent<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=3.%20Built,encryption%20or%20abnormal%20behavior%20occurs\">[2]<\/a>. <\/span><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The team will ensure that these files are deleted or remain in quarantine. <\/span><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: helvetica, arial, sans-serif;\">They also check for any persistence mechanisms (e.g., malicious registry entries, scheduled tasks) \u2013 EDR tools often highlight these. <\/span><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The responders use EDR logs and possibly additional scanning to confirm no remnants of the malware remain on the system.<\/span><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">If the malware altered system settings or created accounts, those changes are reversed. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">In some cases, a full malware removal might require running additional anti-malware scans or using system restore. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Notably, Privacy-i EDR includes a <strong>backup and recovery feature that captured system snapshots<\/strong> right before the attack actions occurred<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=3.%20Built,encryption%20or%20abnormal%20behavior%20occurs\">[2]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The team can leverage this for eradication by rolling back the system to a clean state. For example, if ransomware encrypted files, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Privacy-i EDR\u2019s real-time backup can restore files to their state just before encryption<a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=,encryption%20or%20abnormal%20behavior%20occurs\">[17]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The Incident Response Team will coordinate with IT support to execute such rollback or to restore from known-good backups if available.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">In situations where an endpoint is too compromised, the eradication might involve re-imaging the machine (wiping and rebuilding it). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Privacy-i EDR helps by identifying the timeline of compromise, so the team knows how far back the system needs to be restored. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Eradication also includes <strong>patching any vulnerabilities<\/strong> that the attacker exploited <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">(e.g., if the incident was caused by a known OS vulnerability, ensure the latest patches are applied).<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\"> The team reviews that the endpoint\u2019s OS and applications are up to date to prevent reinfection.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Throughout eradication, the EDR agent remains in place on the endpoint to continuously monitor. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">If any malware traces attempt to execute again, the agent would detect and block them, providing assurance that eradication is effective.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\"><strong>4. Recovery:<\/strong> Once threats are removed, the systems can be returned to normal operation. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The recovery step ensures that business operations resume safely. If machines were isolated, they are reconnected to the network after being verified clean.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\"> Any data that was encrypted or lost is restored from backups. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Thanks to Privacy-i EDR\u2019s <strong>\u201cReal-Time Backup &amp; Restore\u201d capability, full recovery to the last safe state before the incident is possible<\/strong><a href=\"https:\/\/www.isecconference.org\/2024\/eng\/exhibitor_view.html?idx=518#:~:text=3.%20Built,encryption%20or%20abnormal%20behavior%20occurs\"><strong>[2]<\/strong><\/a><strong>.<\/strong> <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The team uses this feature or alternate backup systems to recover any affected files or systems.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">For instance, if a critical file server was impacted by malware, confirm via EDR logs that the malware did not spread there; if it did, restore server data from backups.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">During recovery, the team also <strong>monitors the environment closely for any sign of recurrence<\/strong>. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Privacy-i EDR will be on high alert, and the SOC will watch for any related alerts. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">If the incident was a widespread malware outbreak, the team might run an organization-wide scan <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">(if Privacy-i EDR offers on-demand scanning or by leveraging existing antivirus capabilities) to ensure no other dormant instances of the threat remain.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The Incident Manager declares recovery complete when all affected systems are verified clean, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">are fully patched, data is restored, and normal functionality is confirmed by users or IT. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">At this point, any temporary controls put in place (like blocking rules or network blocks) can be reviewed and removed if appropriate.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\"><strong>5. Post-Incident Activity:<\/strong> After recovery, a <strong>post-incident review<\/strong> is conducted. The Incident Response Team, along with relevant stakeholders, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">will document the incident in detail: timeline of events, how the incident was detected (e.g., \u201cPrivacy-i EDR alert for ransomware on PC X at 10:05 AM\u201d), <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">what actions were taken, and the outcome. They analyze what went well and identify any gaps in the response. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Privacy-i EDR provides logs and reports that are invaluable for this stage \u2013 the team can extract an incident report from the EDR console,<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">including the attack kill chain visualization and all affected objects, to include in the analysis.<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">A lessons-learned meeting is held to discuss improvements. For example, if the incident revealed that a certain malware was not blocked sooner due to a missing detection rule, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">the team will work with the Somansa product team to update detection capabilities. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Indeed, Privacy-i EDR\u2019s integration with threat intelligence ensures that <strong>new threat information is updated in real time across all agents<\/strong><a href=\"http:\/\/somansa.presscat.kr\/en\/product\/edrsummary\/#:~:text=Ransomware%20activity%20is%20saved%20and,TI%29%20systems\"><strong>[16]<\/strong><\/a>, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">so the specific malware encountered will now be recognized and blocked in the future environment-wide. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The team will also consider if additional controls are needed <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">(e.g., increasing user training if the infection started via a phishing email, or implementing network segmentation if needed).<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">Finally, any <strong>compliance reporting<\/strong> is completed. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">If this incident falls under breach notification rules, management (with legal counsel) will use the incident details to inform regulators or customers as required. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">The documented incident response report \u2013 structured as per this plan \u2013 can be submitted <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 12pt;\">as evidence during security audits or compliance reviews to demonstrate that the organization has a formal incident handling process.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<h2 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Incident Severity Levels and Response Times<\/span><\/h2>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">To ensure timely response, incidents are categorized by severity with target Service Level Agreements (SLAs) for response times:\u00a0<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>1. Critical Severity:<\/strong> Incidents that pose an immediate, severe impact on multiple systems or sensitive data (e.g. widespread ransomware outbreak, active attacker on the network).<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"> <strong>Response SLA:<\/strong> Immediate notification and response initiation, ideally within <strong>1 hour<\/strong> of detection. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The Incident Response Team and management must be engaged immediately. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Containment actions (such as isolating systems) begin <strong>as soon as possible<\/strong> (within 1-2 hours), and a full incident team is assembled on a war footing. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Progress updates are given to management frequently (e.g., every 2-4 hours). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Aim to contain and mitigate critical incidents within 24 hours or less, <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">with ongoing monitoring<a href=\"https:\/\/www.reddit.com\/r\/AskNetsec\/comments\/15a89qa\/edrmdr_response_times\/#:~:text=Typically%202%20hours%20can%20be,max%2C%207%20days%20to%20remediate%2Frecover\">[18]<\/a> (industry practices suggest critical incidents be fully contained in 24-48 hours at most).<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>2. High Severity:<\/strong> <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Incidents with significant impact or high likelihood of escalating<\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">(e.g. malware infection on a single high-value system, or attempted data exfiltration that was detected and blocked). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Response SLA:<\/strong> <strong>Prompt<\/strong> \u2013 initiate response within <strong>2 hours<\/strong> of alert. SOC escalates to Incident Response Team on the same business day. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Containment should be achieved swiftly (within a few hours). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">High severity incidents are typically resolved or eradicated within a target of <strong>1-2 business days<\/strong>, with continuous efforts until closure. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Management is kept informed at least daily.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>3. Medium Severity:<\/strong> <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Incidents with moderate impact, or isolated issues that are fully contained by the EDR\u2019s automatic actions <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">(e.g., a malware file was quarantined on one machine, no further spread, and it\u2019s not a novel threat). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Response SLA:<\/strong> <strong>Within one business day<\/strong> for initial analysis. These may be handled largely by the SOC with minimal escalation. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Containment is already in place (since Privacy-i EDR likely stopped the threat), so the focus is on ensuring removal and verifying no broader issues. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Such incidents should be resolved within a few days, and a summary reported in periodic incident reports.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>4. Low Severity:<\/strong><\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Incidents with little to no impact, such as false positives or policy violations that do not involve malware <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">(for example, a user attempted an unauthorized USB access and EDR\/DLP blocked it). <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\"><strong>Response SLA:<\/strong> These are reviewed in routine triage (within 2-3 days) by the SOC or security team. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">They may not require formal incident declaration. Documentation might be limited to logging in the system. <\/span><\/p>\r\n<p style=\"padding-left: 120px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">If any minor action is needed (user follow-up, tuning a rule), it\u2019s done as part of normal operations.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">These SLA guidelines ensure that the response is commensurate with the incident\u2019s severity. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The Incident Manager will adjust actual response actions based on context, but <strong>at minimum the initial response time goals must be met<\/strong>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The organization\u2019s policy is to <strong>detect, contain, and recover from threats quickly and efficiently<\/strong><a href=\"https:\/\/www.wiz.io\/academy\/incident-response-fast-track-guide#:~:text=Incident%20response%20is%20a%20strategic,from%20threats%20quickly%20and%20efficiently\"><strong>[10]<\/strong><\/a>, thereby reducing harm. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Regular drills and tests of this incident response plan are conducted (at least annually) to ensure the team can meet these timelines and to refine procedures.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<h2 style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Additional Notes and Compliance<\/span><\/h2>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">This incident response plan is designed to satisfy security compliance requirements and industry best practices. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">It aligns with frameworks such as NIST SP 800-61 (Computer Security Incident Handling) and ISO 27035. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">All incidents and actions are logged within the Privacy-i EDR system and the incident management system to maintain an audit trail<a href=\"http:\/\/somansa.presscat.kr\/en\/newsevent\/somansa-privacy-i-saas-endpoint-dlp\/#:~:text=were%20quite%20pleased%20to%20see,questions%20about%20your%20system%E2%80%99s%20status\">[8]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">During compliance reviews or audits, this plan and the associated incident records demonstrate our prepared and structured approach to handling security incidents.<\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">The Privacy-i EDR platform\u2019s built-in incident management and reporting features support our compliance efforts <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">by providing detailed evidence of detection and response actions (including the ability to generate reports of incident timelines, affected assets, and response measures). <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Administrators can produce incident reports and dashboards from Privacy-i EDR\u2019s console to show metrics like number of incidents, response times, and outcomes<a href=\"http:\/\/somansa.presscat.kr\/en\/newsevent\/somansa-privacy-i-saas-endpoint-dlp\/#:~:text=were%20quite%20pleased%20to%20see,questions%20about%20your%20system%E2%80%99s%20status\">[8]<\/a>. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">These reports are used in quarterly security reviews and help in continuous improvement of both the product deployment and the incident response process.<\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">By following this plan, the company ensures a consistent and effective response to endpoint security incidents, <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">limiting damage and learning from each event to strengthen defenses.<\/span><\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Somansa Privacy-i EDR, as a key security control, significantly aids in the <strong>rapid detection and response<\/strong> part of the incident response lifecycle, <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">and this document complements the technology with clear human procedures. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">All team members must familiarize themselves with these procedures as part of the MVI onboarding and ongoing security training. <\/span><\/p>\r\n<p style=\"padding-left: 80px;\"><span style=\"font-family: helvetica, arial, sans-serif;\">Regular updates to this document will be made as the product features or organizational structure evolves, or as new types of threats emerge.<\/span><\/p>\r\n<p style=\"padding-left: 40px;\">\u00a0<\/p>\r\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>\u00a0 Somansa Privacy-i EDR\/Antivirus Incident Response Plan &nbsp; Introduction and Purpose &nbsp; This document outlines the procedures for incident response involving Somansa\u2019s Privacy-i EDR, a next-generation endpoint detection and response solution. Privacy-i EDR monitors endpoints in real time for security threats, automatically blocking malware and suspicious behavior on Windows 10\/11 desktops[1][2]. The purpose of this [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-8925","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/pages\/8925","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/comments?post=8925"}],"version-history":[{"count":20,"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/pages\/8925\/revisions"}],"predecessor-version":[{"id":8965,"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/pages\/8925\/revisions\/8965"}],"wp:attachment":[{"href":"http:\/\/somansa.presscat.kr\/en\/wp-json\/wp\/v2\/media?parent=8925"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}