Now that we understand the basic concept of the phases in incident response, let's see how we can integrate these phases to enable cyber intelligence in the organization through reviewing the following diagram:
The Preparation phase of Incident Response is a culmination of policies, procedures, training, and so on that can be mapped to different capabilities within the organization through the use of RASCI matrices. We would see the execution of the processes that are identified in these matrices in the Detection and Analysis and Containment, Eradication, and Recovery phases of the Incident Response ...