Incident Response Guidance from AWS
AWS has taken lessons learned from a number of customer incidents and along with a few other industry-leading resources such as the NIST SP 800-61 Computer Security Incident Handling Guide, compiled a guide to help with Incident Response. This guide is composed of three major sections:
- Preparation: This involves detecting and responding to incidents when they occur in your account(s). This includes the preparation of playbooks and runbooks, which can be manual, automated, or a combination of the two. These allow quick and consistent responses to incidents.
- Operations: This is when the incident has occurred and you are following the NIST phases of incident response: Detect, Analyze, Contain, Eradicate, and Recover.
- Post-incident activity: Once the incident is over, the team needs to take time to understand and record how the events transpired. This is an excellent time to take away any lessons learned and action items to make the response...