Any good attacker will tell you that expensive security monitoring and prevention tools aren’t enough to keep you secure. This practical book demonstrates a data-centric approach to distilling complex security monitoring, incident response, and threat analysis ideas into their most basic elements. You’ll learn how to develop your own threat intelligence and incident detection strategy, rather than depend on security tools alone. Written by members of Cisco’s Computer Security Incident Response Team, this book shows IT and information security professionals how to create an InfoSec playbook by developing strategy, technique, and architecture.
Nicely written for someone who never had to think of Incident Response before. But it read a bit outdated completely missing topics like mobile application security and cloud computing. Topics which most InfoSec organizations need to deal with in this day and age. I disliked how much of the work detailed in this book needed to come from a specialized security team when I think most organizations could benefit from a model where the system engineers and developers themselves are in charge of the monitoring and response of their application.