Planning for Security Operations
As cyber incidents are inevitable, operational security teams should ensure they are prepared to handle them so that response can be swift and efficient. Incident handling involves a prescribed cycle, investigation management, which will be covered in detail in Chapter 17. This chapter will discuss the planning that needs to be done prior to an incident and will focus on the specific operational practices of the incident response cycle that organizations must have in place before an incident even occurs.
A key element of pre-incident activities that organizations need to undertake is preparation for detecting and responding to incidents. This entails ensuring that events are visible and traceable and that the right people, processes, and technologies are in place, tested, and ready for deployment when an incident occurs. The key element of incident planning is operational resilience; the organization should be able to survive any incident, with the...