From the course: CompTIA Cybersecurity Analyst (CySA+) (CS0-003) Cert Prep

Unlock the full course today

Join today to access over 24,700 courses taught by industry experts.

Incident response reports

Incident response reports

- [Instructor] In the aftermath of a security incident, you'll likely find yourself responsible for writing a report summarizing the incident and laying out next steps. Let's take a look at the sections that you would typically include in a report. The executive summary is usually the first section of the report, and it provides a high level overview of the incident. It should be clear and concise, and it should contain key findings and recommendations. The summary should include a brief description of the incident, the impact on the organization, and the scope of the incident. The next section of the report should cover the detailed who, what, when, where, and why of the incident. This section should provide a detailed analysis of the attack, including how the attackers gained access, what data was compromised, and who was responsible for the attack. It should also provide a timeline of the incident, including when the attack was detected and when the response team was activated. The…

Contents