CHAPTER 3
Preparing for Incident Response
 
This book is about incident response. So why include a section on incident response preparation? Why train for a marathon? Why install fire alarms? Preparation is necessary for any well-executed endeavor, and incident response is no exception. Incident preparation is necessary not only to develop your response capabilities, but also to facilitate the response process.
The philosophy behind incident preparation is to create an infrastructure that provides rapid answers to the questions you will have after an incident occurs:
image   What exactly happened?
   What system(s) was affected by the incident? ...

Get Incident Response & Computer Forensics, 2nd Ed., 2nd Edition now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.