[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-169192-en":3,"doc-seo-169192-105":30,"detail-sidebar-cat-1-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":11,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},169192,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",1,158,"General","Incident Response Standard Operating Procedures - December 2021","Incident Response Standard Operating Procedures (SOP) document supports newly formed and established incident response teams in managing key incidents using a correct, ordered approach. It defines core scenarios including root access, virus or ransomware/malware outbreaks, privilege escalation, unauthorized access, improper computer use, phishing, data theft, and denial of service. The SOP provides structured incident handling guidance, outlining detection, initial analysis, investigation, evidence collection, threat categorization, and preparation steps, and allows customization by department responsibilities.","Name of Organization\nIncident Response\nStandard Operating Procedures\nDecember 2021\nRevision History\nInstructions\nThis (Name of Organization) Incident Response Standard Operating Procedure (SOP) is designated For Official Use Only (FOUO) and is the property of (Name of Organization). Only (Name of Organization) representatives may distribute this document to individuals on a need-to-know basis. Distribution by other individuals without prior authorization is prohibited. This document is unclassified but contains sensitive information.\n\u0003Table of Contents\n\u0013 TOC \\o \\h \\z \\u \u0014\u0013 HYPERLINK \\l \"_Toc88584113\" \u0014I.\tIntroduction\t\u0013 PAGEREF _Toc88584113 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584114\" \u0014II.\tIncident Handling\t\u0013 PAGEREF _Toc88584114 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584115\" \u0014Initial Incident Handling Steps\t\u0013 PAGEREF _Toc88584115 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584116\" \u0014Generic Uncategorized Incidents - Handling Checklist\t\u0013 PAGEREF _Toc88584116 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584117\" \u0014Containment, Eradication, and Recovery Checklist\t\u0013 PAGEREF _Toc88584117 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584118\" \u0014III.\tDetailed SOP Instructions\t\u0013 PAGEREF _Toc88584118 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584119\" \u0014Root Access SOP\t\u0013 PAGEREF _Toc88584119 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584120\" \u0014Ransomware/Malware Outbreak SOP\t\u0013 PAGEREF _Toc88584120 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584121\" \u0014Elevation of Privileges SOP\t\u0013 PAGEREF _Toc88584121 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584122\" \u0014Unauthorized Access SOP\t\u0013 PAGEREF _Toc88584122 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584123\" \u0014Improper Computer Usage SOP\t\u0013 PAGEREF _Toc88584123 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584124\" \u0014Virus Outbreak SOP\t\u0013 PAGEREF _Toc88584124 \\h \u001423\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584125\" \u0014Phishing SOP\t\u0013 PAGEREF _Toc88584125 \\h \u001426\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584126\" \u0014Data Theft SOP\t\u0013 PAGEREF _Toc88584126 \\h \u001429\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc88584127\" \u0014DDoS SOP\t\u0013 PAGEREF _Toc88584127 \\h \u001432\u0015\u0015\n\u0015\u0004\nIntroduction\nThis Standard Operating Procedure Document is intended to assist both newly formed and established incident response teams in managing key incidents to the correct approach. More precisely, this document covers the following key scenarios.\nRoot Access - permissions to read, write to and administer systems and operating software\nVirus Outbreak - a virus, worm, Trojan horse, or other malicious entity comprised entirely of code that successfully infects a host\nPrivilege escalations - users receive or manufacture privileges they are not entitled to\nUnauthorized Access - a person gains logical or physical access to a network, system, application, data, or other information technology resource without authorization\nImproper Computer Use - a person violates any network or computer policy governing acceptable use\nRansomware/Malware Outbreak - malware that infected multiple assets and is spreading across networks and computers\nPhishing - sends a fraudulent message designed to trick a human victim into revealing sensitive information to the attacker or to deploy malicious software\nData Theft - extraction or stealing of information\nDenial of Service (DoS) - an attack that prevents or impairs authorized use of networks, systems, or applications through resource exhaustion\nFor each incident there are several key steps to be performed. This document references the key major threats/risk that companies are experiencing and the exact process to follow, by whom, and in what order.\nThe Standard Operating Procedure (SOP) can be customized - if needed - based on the individual needs of departments and Organizational responsibilities.\nIncident Handling\nThe checklist below details the major steps that must be taken during the initial investigation of an incident. The items address only the detection and initial analysis of an incident; thereafter, incident handlers should refer to checklists tailored to the specific type of incident identified.\nThe actual steps taken will vary depending on the type of incident and the nature of the individual incidents. For instance,","cbCaiuzjNeJXGHut","https://ap.wps.com/l/cbCaiuzjNeJXGHut","docx",1503355,34,"English","en",105,"# Introduction\n## Key Incident Scenarios\n# Incident Handling\n## Initial Incident Handling Steps\n## Generic Uncategorized Incidents - Handling Checklist\n## Containment, Eradication, and Recovery Checklist\n# Detailed SOP Instructions\n## Root Access SOP\n## Ransomware/Malware Outbreak SOP\n## Elevation of Privileges SOP\n## Unauthorized Access SOP\n## Improper Computer Usage SOP\n## Virus Outbreak SOP\n## Phishing SOP\n## Data Theft SOP\n## DDoS SOP","[{\"question\":\"What incident scenarios are covered by the SOP?\",\"answer\":\"The SOP covers root access, virus and ransomware/malware outbreaks, privilege escalation, unauthorized access, improper computer use, phishing, data theft, and denial of service (DoS).\"},{\"question\":\"What are the main steps during initial incident handling?\",\"answer\":\"It focuses on checklist-based detection and initial analysis, including categorizing the incident, defining threat indicators, reviewing logs and evidence, building a suspicious behavior timeline, and verifying whether systems are remote-spamming or involved in DDoS activity.\"},{\"question\":\"How can the SOP be adapted for different departments?\",\"answer\":\"The document states the SOP can be customized based on departmental needs and organizational responsibilities, including defining core and extended operations teams and roles.\"}]","Incident Response Standard Operating Procedures - December 2021 | DOCX",1788247913,12,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"incident-response-standard-operating-procedures-december-2021","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/general/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/incident-response-standard-operating-procedures-december-2021/169192/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-05","2026-09-01",true,{"@type":66,"interactionType":67,"userInteractionCount":53},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What incident scenarios are covered by the SOP?","Question",{"text":76,"@type":77},"The SOP covers root access, virus and ransomware/malware outbreaks, privilege escalation, unauthorized access, improper computer use, phishing, data theft, and denial of service (DoS).","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What are the main steps during initial incident handling?",{"text":81,"@type":77},"It focuses on checklist-based detection and initial analysis, including categorizing the incident, defining threat indicators, reviewing logs and evidence, building a suspicious behavior timeline, and verifying whether systems are remote-spamming or involved in DDoS activity.",{"name":83,"@type":74,"acceptedAnswer":84},"How can the SOP be adapted for different departments?",{"text":85,"@type":77},"The document states the SOP can be customized based on departmental needs and organizational responsibilities, including defining core and extended operations teams and roles.","https://schema.org",{"og:url":52,"og:type":88,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,99,103,108,113,118,123,128,133],{"id":95,"doc_module":11,"doc_module_name":46,"category_name":96,"show_sort_weight":97,"slug":98},11,"Presentations",90,"presentations",{"id":29,"doc_module":11,"doc_module_name":46,"category_name":100,"show_sort_weight":101,"slug":102},"Resumes",80,"resumes",{"id":104,"doc_module":11,"doc_module_name":46,"category_name":105,"show_sort_weight":106,"slug":107},14,"Invoices",70,"invoices",{"id":109,"doc_module":11,"doc_module_name":46,"category_name":110,"show_sort_weight":111,"slug":112},15,"Posters",60,"posters",{"id":114,"doc_module":11,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},16,"Social Media",50,"social-media",{"id":119,"doc_module":11,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},17,"Forms",40,"forms",{"id":124,"doc_module":11,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},18,"Letters",30,"letters",{"id":129,"doc_module":11,"doc_module_name":46,"category_name":130,"show_sort_weight":131,"slug":132},21,"Paper Templates",5,"papers-templates",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":4,"slug":134},"general-158"]