Assessing IR in the cloud using the SANS IR model
The SANS IR process has been widely adopted for traditional IR in many organizations. Fortunately, this process, while originally designed for the traditional physical computing environment, applies to both hybrid and full cloud environments. The IR process consists of the following stages:
Figure 11.3: The SANS IR process
For those who do not know anything about SANS, the SANS Institute specializes in information security, cybersecurity training, and certification programs.
In the following sections, we'll take a look at each stage of the SANS IR process in detail, starting with preparation.
Preparation
At this stage, the organization prepares its IR assets and processes. It is usually done well before an incident is reported so that IR can be smoothly executed at a moment's notice. It entails ensuring that there is an IR team at the ready, an efficient communication channel, adequate tools to be...