Incident response team structure
There are different incident response teams, organizations will form them in different ways to support specific roles however, there are some common structures. One of the more popular types is the Computer Security Incident Response Team (CSIRT) which has a basic structure as follows:
- Team Leader: Directs the CSIRT and is responsible for procedures, can report to management or pass that to the incident leader
- Incident Leader: Sometimes called Incident Commander, they coordinate individual responses and orchestrates tasks
- Support Member IT: Infrastructure and Application Experts who know the system or systems
- Support Member Management: Business decision maker, also communicates to employees and board
- Support Member PR: Communicates to the public and clients to maintain business and relationships
- Support Member Legal: Advises of legal outcomes of decisions
This is but one framework structure and as previously discussed...