chapter five

5 Incident Response

 

This chapter covers

  • The difference between events, incidents, and security incidents
  • The four phases of the Incident Response Lifecycle
  • The Incident Response Plan
  • Organization of the Security Operations Center (SOC)

While risk management seeks to lower the likelihood and minimize the impact of risks, some risks can never be completely eliminated. Undesired events in the form of cyberattacks or equipment failures will make risks materialize and can cause significant damage if not resolved effectively. We define an incident as any undesired event that causes, or could cause, disruption or damage.

To protect themselves from disruptions to their business operation and damages to assets, organizations implement an incident response strategy that detects incidents and then takes action to mitigate, contain, and resolve them. When incident response is effective, it enables organizations to respond more efficiently, reducing downtime, operational costs, and potential business impact. A central aspect to this strategy is the creation and maintenance of an incident response plan, collecting data and feedback to continually improve it, and organizing teams around it.

5.1 Why is Incident Response Important?

5.2 Events, Incidents, and Security Incidents

5.3 Incident Response Lifecycle

5.3.1 Preparation

5.3.2 Detection and Analysis

5.3.3 Containment, Eradication, and Recovery

5.3.4 Post-Incident Activity

5.4 Incident Response Plan

5.5 The Security Operations Center (SOC)

5.5.1 SOC Structure

5.5.2 Escalation

5.6 Closing Thoughts

5.7 Summary

5.8 Review Questions

5.9 Answers to Review Questions