The Goals of Incident Response
The goals of IR can be broken down into short-term and long-term goals. Ultimately, you want to be in a position where you no longer have to engage in IR. A short-term goal for an organization may be to ensure that all the logging is in place and notification systems are enabled in case of an incident. Long-term goals may take the form of compiling scripted playbooks with detailed steps so that new team members can quickly and efficiently respond to an incident or, better yet, prepare automated responses. For instance, services such as Systems Manager documents and Lambda functions that trigger automatically based on items found in logs mean no person needs to respond. The response happens before anyone can even turn on their computer.
It all begins with having a plan. A playbook with scripted steps that you or other team members can follow can relieve the stress of an event. An automated runbook or predefined templates (such as CloudFormation templates...