3 THE INCIDENT RESPONSE PROCESS

During a security incident there will be panic, there will be confusion, there will be stress, and there may also be a degree of anger. Few situations lead to such an emotional display among information technology professionals as when they are faced with the prospect that someone uninvited found their way into their network, system or application. I’ve even heard it described by one developer, whose application was compromised by a Structured Query Language (SQL) injection attack, as ‘a feeling similar to someone physically breaking into your home’.

As security incident handlers, we have a duty to remove the emotion from the situation, and keep the response occurring in the most orderly way possible. The security ...

Get Hands-on Incident Response and Digital Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.