Preparation and planning – developing an effective incident response plan
There are many aspects that must be considered during the planning phase. Let’s cover them one by one:
- Defining a workflow: Most frequently the process is presented as a block diagram divided into layers (vertical axis) and milestones (horizontal axis).
The layers could be organized in many ways:
- Incident response team (analysts), incident response team lead, and management team
- Incident source, incident response team, and subject matter experts (in case of existing escalation procedures)
The milestones can be grouped in the following ways:
- Detect and verify, investigate, remediate (contain, eradicate, recover), lessons learned
- Identify and verify, investigate and contain, eradicate and recover, lessons learned (post-incident activity)
- Identification, coordination, resolution, closure, continuous improvement
This is important to understand the key steps, their prerequisites, and the exit...