Summary
Effective IR is critical in organizations due to the growing number of security threats. However, due to unfamiliarity with relevant tools as well as the use of trial-and-error methods, many organizations end up failing during IR exercises. A more effective way of approaching the process is by using a systematic method that will significantly improve the chances of success. Derived from the military, the OODA loop is designed to guide organizations through the four main phases of IR. The loop starts at the Observe stage, where security teams find out more details about suspected or confirmed incidents. The second phase is Orient, which entails gaining an understanding of the adversary and the target. This information gives the security team key insights about a security incident that will affect how and when the security event will be resolved. The third stage is Decide, whereby key security decision-makers come up with the optimal way of resolving an incident using the intelligence...