Module 4 Flashcards
Playbook
A manual that provides details about any operational action
Incident Response Playbook Phases
Preparation
Detection and analysis
Containment
Eradication and recovery
Post incident activity
Coordination
Preparation
Before incidents occur, mitigate potential impacts on the organization by documenting, establishing staffing, plans, and educating users
Detection and Analysis
Detect and analyze events by implementing defined processes and appropriate technology
Containment
Prevent further damage and reduce immediate impact of incidents
Eradication and Recovery
Completely remove artifacts of the incident so that an organization can return to normal operations
Post-Incident Activity
Document incident, inform, organizational leadership, and apply lessons learned
Coordination
Report incidents and share information throughout the response process, based on established standards