Which of the following activities is a critical component of the 'Preparation' phase of the security incident handling process, according to the NIST framework?
-
A
Analyzing system logs to determine the scope of a breach.
-
B
Restoring data from backups after a ransomware attack.
-
C
Establishing and training a Computer Security Incident Response Team (CSIRT).
-
D
Disconnecting an infected machine from the network.