Chapter 18: Incident Response for the ICS Environment
Our journey through industrial cybersecurity monitoring and validation is almost over. So far, we have mostly concentrated on how to verify the security of our industrial environment. In this final part of this book, we are going to discuss how to prepare for mayhem and how to handle things in case we find ourselves facing security-related incidents, as well as what to do when things go wrong.
In this chapter, we will be discussing the ins and outs of setting up and maintaining an incident response plan. We will outline the phases, activities, and processes of incident response as it relates to the industrial environment. You will learn how by maintaining clear-cut and detailed processes and procedures around the incident response plan, you will set yourself up for success when dealing with security incidents.
We will cover the following topics in this chapter:
- What is an incident?
- What is incident response? ...