Observation Window
Definition
A defined period after a system is restored during which enhanced monitoring is applied before the system is declared fully recovered. The window allows detection of residual compromise that was not eliminated during eradication, or reinfection through a vector not yet closed.
- Field
- Incident response, system recovery
- Timing
- After system restoration, before declaring full recovery
- Purpose
- Enhanced monitoring to detect residual compromise or reinfection
- Position in lifecycle
- Between eradication and closure
Common questions
How long does an observation window typically last, and what determines that duration?+
Duration varies by incident severity and the attacker's demonstrated persistence techniques, ranging from days to several weeks; responders extend it if any suspicious activity reappears and shorten it once monitoring confirms no residual indicators of compromise across enough business cycles to be confident.
What specifically is monitored differently during an observation window compared to normal operations?+
Teams typically increase logging verbosity, watch for reconnection attempts from previously identified attacker infrastructure, monitor for the reappearance of malware indicators, and review authentication logs more closely for anomalous access patterns that would suggest an unclosed vector.
What happens if suspicious activity is detected during the observation window?+
The incident is generally reopened rather than treated as a new event, since activity during this window most often indicates the original eradication was incomplete or a vector was missed, requiring the response team to return to containment and eradication steps before restarting the window.
Related terms
- Clean Baseline
- A confirmed, verified system state that predates the compromise and is free from attacker artefacts. Establishing a clean baseline is the starting...
- Dependency Mapping
- The process of identifying all services, systems, and data flows that a given system depends on, and all systems that depend on...
- Recovery Point Objective (RPO)
- The maximum acceptable amount of data loss measured in time. It defines how far back in time the organisation is willing to...
- Recovery Time Objective (RTO)
- The maximum acceptable duration of downtime before a system must be restored to service. RTO drives decisions about recovery method: a short...
- Rollback Plan
- A documented procedure for reverting a recovery attempt if it fails or introduces new problems. A rollback plan specifies trigger conditions, the...