Overview
Incident Response (IR) is the process by which an organization handles a data breach or cyberattack, including the way the organization attempts to manage the consequences of the attack. The goal is to limit damage and reduce recovery time and costs.
The SANS Incident Response Steps
- Preparation: Establishing an IR team and tools.
- Identification: Detecting and validating the incident.
- Containment: Limiting the scope and impact of the breach.
- Eradication: Removing the threat from the environment.
- Recovery: Restoring systems to normal operation.
- Lessons Learned: Documenting the incident to improve future response.
Incident Response Plan (IRP)
A formal document that outlines the procedures to be followed in the event of a security incident, ensuring a consistent and effective response.