Understanding the incident response process
The incident response process is broken down into six distinct phases. Each of these phases is important and must be completed before moving forward. The following diagram shows these distinct phases:
Now, let's discuss these six phases.
Preparation
While preparing for an IRP, it is a good practice to harden systems and mitigate security vulnerabilities to ensure a strong security posture is in place. In the preparation phase, it is normal to increase the enterprise's resilience by focusing on all the likely attack vectors. Some of the tasks that should be addressed to prepare your organization for attacks include the following:
- Perform risk assessments
- Harden host systems
- Secure networks
- Deploy anti-malware
- Implement user awareness training
It is important to identify common attack vectors. While it is almost impossible to...