Incident tasks – to do or not to do
Recently, I was involved in a project around incident tasks (some know it as incident workflows or incident playbooks) and had the opportunity to speak with many people about it. This is the reason why I decided to have a dedicated section about one important segment in incident management.
As I wrote in the previous section, a few dozen incidents happen daily in our SOCs. Some of them are new, but some of them are only seen sometimes. If there is a new incident that our SOC analyst has never worked on before, it will take some time to investigate it properly. But if someone else had already been investigating that incident before and had written the lessons learned, it would be easy for the SOC manager to create a list of steps that should be taken to investigate this incident. In this case, our SOC analyst will save valuable time figuring out steps that they need to perform, and it is possible to go through the list of tasks that have...