Incident response procedure development

Incident response procedures are a tactical component of the incident response capability, whereby the incident responder has clearly documented repeatable processes, which allow the incident responder to conduct the activities necessary to do the following:

  • Detect and analyze whether a threat exists
  • Contain, eradicate, and recover from a threat

When it comes to incident response procedures you will want to implement a checklist approach that allows your incident responders to have clear instructions and guidance, including all the necessary steps to conduct a specific incident response activity. The following sample is a recommended checklist that your organization should implement:

  • Emergency contact ...

Get Information Security Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.