From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Incident response plan

Incident response plan

- Eventually, a security incident is going to occur. It's just a matter of time. And when it does, how is your organization going to respond? Well, the way we respond to an incident will determine just how much damage that incident can cost our organization and how much it's going to cost us in reputation, time, and money. Therefore, it's important for us to think about how we're going to respond before it is actually time for us to respond. And so it's a great idea to have an incident response plan in place. This plan should be formally written, well communicated across the organization, and most importantly, it needs to be followed during an incident. There are six steps to every good incident response: Detection, response, report, recover, remediate, and review. Let's take a minute to look at each of these. First, we have detection. If you haven't detected the incident, then we can't start responding to it. The key to detection is using good detective controls, things like logging…

Contents