sans-phases
April 25, 2020

Incident Response : Phases & understanding them better

By venkat
  1. Incident response is a living process that changes constantly depending on the situation. [1]
  2. Generally there is a failure to understand the difference between containment and eradication. “Many people feel that if you go directly to eradication, we’re essentially achieving containment because we’re eradicating at the same time,”.
  3. The reason containment exists, Lee says, is that it gives incident response teams time to do proper scoping of the incident. This goes back to the identification phase, which some organizations confuse. The identification phase isn’t about intrusion detection, it’s about determining how bad the cancer is within your organization.

Our sincere thanks to Rob Lee [2] & SANS

Basic Phases

https://atc-project.github.io/atc-react/responsestages/

Example Playbook showing the phases

Phishing-Basic-Mitigations
CLICK & experience the playbook