The OODA loop
Organizations are increasingly following a military-derived technique known as the Observe, Orient, Decide, Act (OODA) loop, illustrated in Figure 5.1, as a guide to the actions and tools required for each major stage of the IR process. The loop is not designed to be rigid, meaning that organizations can integrate it with their preferred IR procedures:
Figure 5.1: OODA loop
You may be wondering why we're basing this chapter around a military tactic. Imagine you are an F15 pilot, and you are in a high-speed dogfight and you need a tool to determine the best way to act in the smallest amount of time. When you think about IR, while under attack, don't we need to take decisions in a minimal amount of time in a similar way?
The first step in the OODA loop is Observe, which is all about evaluating what's going on in the cybersecurity landscape and inside your organization.
Observe
This is the initial stage of the OODA loop, where...