The incident management process
Preparedness is essential for being effective in the event of a significant incident. This is a common-sense statement, yet it is not always followed in practice. In most cases, only after a few major incidents have occurred it is common for an organization to develop a set of incident-handling procedures, testing and adjusting those processes to meet its needs. Some organizations only equip themselves to handle an issue in part, and a comprehensive system that can deal with any form of an incident may not be present.
The first step is to find out which security events should be investigated, and at what thresholds, by also considering the business continuity requirements of the organization. The next step is to draft a response strategy for each different kind of incident. It is possible to improve it through security event simulations, which allow you to uncover gaps in your process, but it will also be improved after actual events have occurred...