Security Incident Response Lifecycle
Microsoft follows a 5-step incident response process when managing both security and availability incidents for the Azure services. The goal for both types is to restore normal service security and operations as quickly as possible after an issue is detected and an investigation is started. The response is implemented using a five-stage process illustrated in Figure, and described in Table, which shows the following activities - Detect, Assess, Diagnose, Stabilize, and Close. The Security Incident Response Team may move back and forth between diagnose to stabilize as the investigation progresses.