Incident Investigation Closure and Reporting
Throughout the book, we have been focusing on technical aspects of the incident response (IR) and handling phases. Chapter 3 introduced IR team (IRT) roles and responsibilities and a process overview. In Chapter 12, several metrics were introduced to align with business on various actions that might interrupt business processes and affect continuity.
The chapter will start with the incident closure process, covering all necessary types of reports, supporting files such as evidence acquisition and handover forms, responsibilities, and quality assurance. Then, the committee review, submission, and closing of the case will be described and applied to IRT roles. Once the paperwork is done, the committee review is passed, and visibility over the impact is achieved, the management team can trigger or close the external incident escalation to regulators, third parties, and law enforcement agencies.
By the end of this chapter, the reader will...