Like business continuity / disaster recovery, incident response is not something you want to test as part of an active incident. You must ensure that you adequately test your overall incident response capability on a periodic basis:
- Active exercise:
- Red team: Utilizing information security experts that are skilled in penetrating networks you can perform activities that simulate an actual network attack.
- Blue team: Utilizing your information security defenders and automation tools work to actively identify and remediate the network intrusion.
- Purple team: The two teams work together rather than working as adversaries. The purple team combines the efforts of the other two teams, with the added benefit of collaboration, ...