
136 SOFTWARE QUALITY ASSURANCE
f. Have changes been made to prevent a reinfection? Have
all systems been patched, systems locked down, passwords
changed, antivirus updated, e-mail policies set, and so on?
g
.
H
ave changes been made to prevent a new and similar
infection?
h
.
S
hould any security policies be updated?
i. What lessons have been learned from this experience?
*
Initiate Recovery Mechanisms
Review Preliminary Investigation Results
• Determine what can and cannot be recovered (systems, com-
puter hardware, computer software, applications, and data)
• Ascertain when each system, entity, and component can and
should be restored
• Te