In this chapter, we looked at some of the recommendations regarding how to prepare for when a security incident occurs and some of the methods, services, and techniques that can be used to identify, isolate, and minimize the blast radius of damage across your environment.
Should you ever be contacted by AWS regarding a security incident, you must follow their instructions immediately and implement your own level of IR in coordination with AWS's requirements.
The key to successful IR is planning and preparation. If you have read through this chapter well enough and have performed this element sufficiently, then you now stand a far higher chance of gaining control of an incident quickly and effectively. Preparation is, in fact, the first element of the IR life cycle within NIST Special Publication 800-61. Due to this, you must prepare for incidents and ensure you have your logging, auditing, monitoring, and detection services and features configured. You also need to have a...