Components of an incident response plan
Based on the NIST framework, there are six components to an IR plan. These are preparation, identification, containment, eradication, recovery, and reporting:
Figure 1.1: Core IR steps covered in this book
We will discuss elements of these steps in detail in later chapters, but for now let's go over what they fundamentally consist of.
Step 1: Preparation
This is one of the most important steps of IR. At this stage, the organization must prepare for different eventualities by answering several questions about the IR plan. Some of these questions are asked and explained as follows.
How will the organization be notified about incidents? Simply put, an IR plan should be tailored to address the sources of information about these incidents to ensure quick recovery. In an organization, notifications about incidents could come from a variety of sources. To begin with, users can report incidents in scenarios where they...