Summary
In this chapter, we learned how to assess an organization's IR capacity.
We also learned how to create an IRP considering the business's characteristics and develop playbooks with actions to respond to specific incidents.
Finally, we learned how to perform atomic tests that allow us to emulate attacks and thus identify threat detection blind spots and evaluate the effectiveness of IRPs.
In the next chapter, you will learn how to implement and use an IR system (IRS).