What an IR team does
IR teams, in general, respond to security events in organizations. While automation can take up many tasks in an organization, IR remains a process primarily reserved for humans. The reason why an IR team is necessary is that the roles that it collectively carries out are at times undefined, unpredictable, and widely scoped. In its operations, the response team does a thorough analysis of all cybersecurity incidents.
Figure 3.2: An IR team analyzes information, discusses observations and activities, and shares important reports and communications across the company
The end goal of an IR team is to minimize the impacts of a security event, ensure the quick restoration of affected processes, and prevent similar incidents from occurring in the future. With this aim in mind, the team collectively carries out the following critical functions:
- Investigation/analysis: A security event could have multiple implications and a diverse team can assess...