Incident response metrics in the cloud
It's worth noting that all of the metrics we have learned about so far will apply to the cloud as well as more traditional infrastructure-based networks. Regardless of where your data or infrastructure resides, you should carefully consider your IR planning, as every cloud provider makes it very clear that security in the cloud is a shared responsibility. While the vendor provides the security controls and capabilities to help protect the organization's data and applications, you, as the IR lead or customer, must also take ownership over your data and identities, and take on the responsibility of protecting them. Obviously, while the security of on-premises resources is under the control of the in-house IR team, the control of cloud components varies by service type.
A best practice for IR in the cloud is ensuring that IR teams are trained on the cloud provider your organization uses. Create playbooks that prescribe standard procedures...