Preparing for Incident Response
This book is about incident response. So why include a section on incident response preparation? Why train for a marathon? Why install fire alarms? Preparation is necessary for any well-executed endeavor, and incident response is no exception. Incident preparation is necessary not only to develop your response capabilities, but also to facilitate the response process.
The philosophy behind incident preparation is to create an infrastructure that provides rapid answers to the questions you will have after an incident occurs:
What exactly happened?
What system(s) was affected by the incident? ...