This document discusses the importance of having a structured incident response process and methodology. It outlines the SANS Six Step incident response methodology, which includes preparation, identification, containment, eradication, recovery, and follow-up. An example incident involving a worm at Example Corporation is provided to illustrate how having a structured response process allows the organization to more effectively identify, contain, and recover from the incident. The document emphasizes that response is an important part of the overall security prevention, detection, response model and that having a standardized methodology helps ensure all necessary steps are followed during an incident.
Related topics: