Preparation
The Preparation phase is the initial phase of the IR life cycle. This phase focuses on establishing the foundation for effective IR capability. This includes the establishment of the following:
- IRT
- IR documents
- Tools
- Tabletop exercises and training
- BC and DR plans
These elements help to prepare an organization to detect, respond to, and recover from security incidents in a coordinated and efficient manner. This phase is imperative to lay the groundwork for this timely and effective response. The rest of this section will go into greater detail on each of these items.
IR Documents
As an organized framework for efficiently addressing and mitigating security issues, IR documents are essential parts of an organization’s cybersecurity strategy. These documents include the following:
- Policies
- IRP
- Procedures
- Playbooks
They serve as a thorough guide to delineate the roles, responsibilities, and coordinated actions...