Educate
You need to make sure that people are comfortable with their role and responsibilities during an incident. Depending on the type of incidents, there might be different individuals who might be responsible for handling it.
For example, when the network goes down due to some technical issue, that incident should be handled by the network administrator instead of the security engineer.
There will be incidents where collaboration might be needed between different people.
Thus, having clear-cut roles and responsibilities and making the employee aware of that is an important part of incident handling.
On top of this, running drills on a regular basis is also important and will help the incident-response team get familiar with the IRP and ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access