Incident Response Plan
Incident Response Process
- Preparation: Help prepare the appropriate people to respond
- Identification: Determine if an event is a security incident
- Containment: Limit the damage of the incident and isolate impacted systems
- Eradication: Find the cause and remove any systems that may be causing harm
- Recovery: Return to normal operation
- Lessons learned: Document everything and analyze to learn and improve
Incident Response Plan Contents
- Documented incident definitions
- Incident response teams
- Reporting requirements / escalation
- Retention policy
- Stakeholder management
- Communications plan