Crafting an Incident Response Plan
Andrew Gorecki
Abstract
Andrew Gorecki
Abstract
Having an incident response plan is a critical step in cyber breach response. An effective incident response plan encompasses an incident management process, roles and responsibilities, communication flows, escalations, and postmortem activities, among other components. This chapter discusses the incident response lifecycle, how to build an effective incident response plan, and how to improve incident response capabilities continuously. The chapter provides a list that describes common activities that enterprises may undertake as part of the preparation phase for an incident. The scope of an incident management process encompasses all cyber security incidents that negatively impact an enterprise, not only cyber breaches. Enterprises can leverage service level agreements and operational level agreements to ensure that entities that participate in the incident management process complete their tasks within the expected time frame and to the agreed-on quality. The chapter also discusses generic content and recommendations that enterprises may choose to include in their incident response playbooks.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Having an incident response plan is a critical step in cyber breach response. An effective incident response plan encompasses an incident management process, roles and responsibilities, communication flows, escalations, and postmortem activities, among other components. This chapter discusses the incident response lifecycle, how to build an effective incident response plan, and how to improve incident response capabilities continuously. The chapter provides a list that describes common activities that enterprises may undertake as part of the preparation phase for an incident. The scope of an incident management process encompasses all cyber security incidents that negatively impact an enterprise, not only cyber breaches. Enterprises can leverage service level agreements and operational level agreements to ensure that entities that participate in the incident management process complete their tasks within the expected time frame and to the agreed-on quality. The chapter also discusses generic content and recommendations that enterprises may choose to include in their incident response playbooks.
Key concepts: Incident response, Incident management, Incident report, Plan (archaeology), Scope (computer science), Leverage (statistics), Process management, Process (computing)