Introduction to incident response
IR is the process by which an organization handles situations such as data breaches, distributed denial of service (DDoS), and ransomware attacks. It is an effort to immediately identify an attack, mitigate the impacts of the attack, contain any damage caused by the attack, and fix the cause in order to reduce the risk of future attacks. In practice, IR refers to a collection of information security rules, processes, and tools that can be used to detect, contain, and remove intrusions. Let’s discuss the two most popular IR frameworks, the National Institute of Standards and Technology (NIST) and SANS, as shown in the following diagram.
Figure 5.1 – NIST and SANS IR
Different methods of incident response process
There are various methods for developing a structured IR process. There are two IR frameworks and processes that are most popular: NIST and SANS. Let us see each of them in detail.