Stick to the plan
When the incident occurs, it is important that the incident-response team sticks to the plan.
There are organizations which create a drill event that might trigger the incident-response program every month, which will make sure that everyone sticks to the plan.
Having understood the three important elements of an IRP, while handling incidents, it is also important to have a run playbook instead of having a 50-page standard procedure document. When the rule event comes, it might not be the first time that it has occurred, so the incident-response team needs to act quickly according to the playbook.
Having said that, insider threats are becoming one of the concerns in today's organizations and since the employee might have ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access