Chapter 13: Implementing Incident Handling
Incident handling plays a vital role within the field of cybersecurity. While there are many professionals who work continuously to discover vulnerabilities and remediate them, there are also professionals who perform incident response to reduce the impact of a security incident.
Throughout the course of this chapter, you will learn about the importance of implementing the recommendations of the National Institute of Standards and Technology (NIST) 800-86 guidelines to help improve the forensic processes of incident response. You will also discover how security teams can share security-related information about computer security incidents with other groups and organizations without revealing sensitive details. Within this chapter, you will also discover how security teams such as a Security Operations Center (SOC) use various models, such as the Cyber Kill Chain and the Diamond Model of Intrusion Analysis, to understand how threat actors...