Incident Response Procedures
Before we start making incident response plans, we need to have a process in place, and the process we are going to use is as shown in Figure 12.1:
The incident response process must be carried out in order, starting with stage 1, which is the preparation phase. Let’s look at these stages in order:
- Preparation: The preparation phase is where the different incident response plans are written and kept up to date. System configurations are documented as well.
- Identification: Once an incident has occurred, it is important that the appropriate incident response plan is invoked, and that stakeholders and the incident response team for that particular incident are notified.
- Containment: At this stage, we will isolate or quarantine computers, to prevent the attack from spreading any further and collect the volatile evidence. We will disable any accounts used by the...