Building the incident response team
Each team identified from previous meetings for building enterprise support for incident response will need to identify resources with areas of expertise that can be committed to incident response in the event the process is triggered. The capacity in which they are engaged is dependent on the severity of the incident and may serve in an advisory role for less severe incidents. Each assigned resource must be made aware of the responsibility of being a member of the incident response team and respond within agreed service-level agreements (SLAs).
The confidentiality of security incidents is as important as a forensic investigation and should be treated as such until the full impact of the incident is understood and communication should be sourced from the communications role in the incident response plan.
Each team member will need to know the correct procedures for already defined incident types, but also be agile enough to take the correct action if an...