2020Unpublished venueRequires access

Crafting an Incident Response Plan

Andrew Gorecki

Open publisher page 1 citations

Abstract

Having an incident response plan is a critical step in cyber breach response. An effective incident response plan encompasses an incident management process, roles and responsibilities, communication flows, escalations, and postmortem activities, among other components. This chapter discusses the incident response lifecycle, how to build an effective incident response plan, and how to improve incident response capabilities continuously. The chapter provides a list that describes common activities that enterprises may undertake as part of the preparation phase for an incident. The scope of an incident management process encompasses all cyber security incidents that negatively impact an enterprise, not only cyber breaches. Enterprises can leverage service level agreements and operational level agreements to ensure that entities that participate in the incident management process complete their tasks within the expected time frame and to the agreed-on quality. The chapter also discusses generic content and recommendations that enterprises may choose to include in their incident response playbooks.

About this research paper

What this paper is about

Having an incident response plan is a critical step in cyber breach response. An effective incident response plan encompasses an incident management process, roles and responsibilities, communication flows, escalations, and postmortem activities, among other components. This chapter discusses the incident response lifecycle, how to build an effective incident response plan, and how to improve incident response capabilities continuously. The chapter provides a list that describes common activities that enterprises may undertake as part of the preparation phase for an incident. The scope of an incident management process encompasses all cyber security incidents that negatively impact an enterprise, not only cyber breaches. Enterprises can leverage service level agreements and operational level agreements to ensure that entities that participate in the incident management process complete their tasks within the expected time frame and to the agreed-on quality. The chapter also discusses generic content and recommendations that enterprises may choose to include in their incident response playbooks.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Having an incident response plan is a critical step in cyber breach response. An effective incident response plan encompasses an incident management process, roles and responsibilities, communication flows, escalations, and postmortem activities, among other components. This chapter discusses the incident response lifecycle, how to build an effective incident response plan, and how to improve incident response capabilities continuously. The chapter provides a list that describes common activities that enterprises may undertake as part of the preparation phase for an incident. The scope of an incident management process encompasses all cyber security incidents that negatively impact an enterprise, not only cyber breaches. Enterprises can leverage service level agreements and operational level agreements to ensure that entities that participate in the incident management process complete their tasks within the expected time frame and to the agreed-on quality. The chapter also discusses generic content and recommendations that enterprises may choose to include in their incident response playbooks.

Key concepts: Incident response, Incident management, Incident report, Plan (archaeology), Scope (computer science), Leverage (statistics), Process management, Process (computing)

Related papers

Back to paper searchBrowse research topicsOriginal source
Crafting an Incident Response Plan — Research Paper | ScholarLens