CHAPTER 3
Preparing for Incident Response
 
This book is about incident response. So why include a section on incident response preparation? Why train for a marathon? Why install fire alarms? Preparation is necessary for any well-executed endeavor, and incident response is no exception. Incident preparation is necessary not only to develop your response capabilities, but also to facilitate the response process.
The philosophy behind incident preparation is to create an infrastructure that provides rapid answers to the questions you will have after an incident occurs:
image   What exactly happened?
   What system(s) was affected by the incident? ...

Get Incident Response & Computer Forensics, 2nd Ed., 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.