Chapter 9

Cybersecurity Operations (CyberOps), Incident Response, Digital Forensics, and Threat Hunting

Chapter Objectives

After reading this chapter and completing the exercises, you will be able to do the following:

  • Prepare for a cybersecurity incident.

  • Identify a cybersecurity incident.

  • Understand the incident response plan.

  • Understand the incident response process.

  • Understand information sharing and coordination.

  • Understand threat intelligence and how to operationalize it.

  • Identify incident response team structure.

  • Understand federal and state data breach notification requirements.

  • Consider an incident from the perspective of the victim.

  • Create policies related to security incident management.

  • Understand the threat hunting process.

  • Understand ...

Get Developing Cybersecurity Programs and Policies in an AI-Driven World, 4th Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.