Hi All —
I have been tasked with developing a document for what to do if a network has had an intruder (ie — remove it from the network, save the logs, contact the authorities, etc). Is there a template that businesses follow out there on the net? If so, can someone point me in the right direction?
Thanks in advance.
Mike