Incident Reporting
So far, we have learned what Incident Response (IR) is, how to build your IR team, and key metrics to monitor. We've also looked at incident handling and taken a deep dive into incident investigation. Now it's time to learn how to report incidents.
When a cybersecurity incident occurs, the organization should take responsibility for reporting details about the breach to various different entities. However, the information that is reported to each entity differs, as organizations should disseminate information on a need-to-know basis when reporting security incidents. This ensures that each entity only accesses the information that is most relevant or essential to them and avoids divulging too much information to some entities or withholding crucial details from others. This chapter goes over the appropriate form of reporting to four key entities: the IR team, the Security Operations Center (SOC) team, third parties, and the media.
Phishing emails...