Managing Cyber Incidents

The incident response framework detailed in the previous chapter provided the specific structure of a Computer Security Incident Response Team (CSIRT), and how the CSIRT will engage with other business units. The chapter further expanded on the necessary planning and preparation an organization should undertake to address cyber incidents. Unfortunately, planning and preparation cannot address all the variables and uncertainties inherent in cyber incidents.

As the boxer Mike Tyson said:

"Everyone has a plan until they get hit in the face."

This chapter will focus on executing those plans and frameworks detailed in Chapter 1, Understanding Incident Response, to properly manage a cyber incident. A solid foundation in ...

Get Digital Forensics and Incident Response - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.