Incident response processes
There are two distinct aspects to incident response:
- Incident response preparation
- Incident response handling
The incident response preparation process occurs periodically without any identified incident. The incident handling process is triggered when an incident is detected.
Incident response preparation process
The goal of the preparation phase of incident response is to prepare the Industrial Control System (ICS) or OT security team to handle incidents efficiently and effectively. By its nature, the preparation phase occurs separately from any identified incident or event.
Creating and maintaining an incident response policy document (we want to record and track our IR processes and procedures), and the related processes and procedures documents, is at the heart of the preparation phase. The incident response preparation process includes both tasks intended to help prevent incidents and tasks intended to streamline incident...