Summary
This chapter delved deeply into the challenges of the incident response process. We looked at how to divide roles in the team, how to build interaction, and what points should receive special attention from the management’s point of view. As a result, we have built a foundation for developing an effective incident response plan covering preparation, detection, verification, classification, analysis, containment, eradication, and recovery steps. The lessons learned, also known as post-incident activities, are also very important, and will be covered in Chapter 13 of this book.
In the next chapter, we will cover the technical aspects of incident analysis with in-the-wild examples, keeping in mind both the attacker’s view of the situation and an effective incident response plan.