Summary
IR planning is important to organizations as it readies them for turbulent times when security events happen. However, to offer maximum utility to an organization, the IR process has to be timely, highly effective, and efficient. This chapter has focused on some of the best practices that organizations can use to ensure the best outcomes in IR.
To begin with, organizations have to adopt proactive mobilization such that they are not caught by surprise by incidents. In addition, IR plans should have a well-defined and easy-to-implement resolution process. The plans should not be overly ambitious such that the resources in an organization cannot support it. Furthermore, IR should use effective communication strategies, without information silos. Only the communications personnel should responsible for providing updates to avoid disrupting the activities of other members of the IR team. Continuing, organizations should battle test their IR plans to acquaint the response team...