The composition of an IR team
This section covers all the individuals that are involved in handling an incident, and their individual roles in ensuring recovery. The section will cover in detail all the personnel and non-personnel aspects that relate to incident cases in organizations.
The section will start with the team lead, who is the primary handler of an incident.
Team lead
The IR team has to have a primary handler who remains in touch with all other team members in the response process. The primary handler carries out the following processes:
- Coordination of activities: An IR team is diverse and carries out many tasks. For instance, the auditors will try to find the cause of the incident, the security team will try to maintain the security of other systems, IT officers will try to move operations to other sites, and the communications department will try to assure customers that the company is responding to the security event. These activities can be...