The incident response process
Incident response like many other things goes through a process, this process is defined by six major phases:
- The Preparation Phase
- Detection Phase
- Analysis Phase
- Containment and Eradication Phase
- Recovery Phase
- Post-Incident Activity Phase
These phases define the core elements of any incident response plan. Now let’s take a look at them in detail.
The preparation phase
In this initial phase the groundwork is laid for handling and supporting incidents when they occur. This means creating the teams, developing processes and procedures, acquiring tools, getting buy in from management. The preparation phase also includes setting up the structure and processes that will be following some of those items include:
- Creating processes for communications, this includes:
- The incident response team: Naming the team members that will be part of this group, this can sometime be group names with members added to...