Introduction
The importance of incident response planning
()
The need for a plan
()
The incident response life-cycle
()
1. Incident Response Planning
Events and incidents
()
Policy, plans, and procedures
()
Elements of a policy
()
Elements of a plan
()
Elements of a procedure
()
2. Incident Response Team
Incident response team structure
()
Different team models
()
Selecting a team model
()
Incident response personnel
()
Leading the team
()
Organizational dependencies
()
3. Communication
Coordinating your efforts
()
Internal information sharing
()
Business impact analysis
()
Technical analysis
()
External information sharing
()
4. Preparation
Preparation
()
Communications and facilities
()
Hardware and software
()
Technical resources and information
()
Software resources
()
Incident prevention
()
5. Detection and Analysis
Attack vectors
()
Detecting an incident
()
Indicators of compromise
()
Conducting analysis
()
Documenting the incident
()
Prioritizing the incident
()
Notification procedures
()
6. Containment, Eradication, and Recovery
Containment strategies
()
Evidence collection and handling
()
Identifying the attacker
()
Eradication and recovery
()
7. Post-Incident Activity
Lessons learned
()
Metrics and measures
()
Retaining the evidence
()
Calculating the cost
()
Conclusion
What to do next
()