Create, maintain, and manage a continual cybersecurity incident response program using the practical steps presented in this book. Don't allow your cybersecurity incident responses (IR) to fall short of the mark due to lack of planning, preparation, leadership, and management support. Surviving an incident, or a breach, requires the best response possible. This book provides practical guidance for the containment, eradication, and recovery from cybersecurity events and incidents. The book takes the approach that incident response should be a continual program. Leaders must understand the organizational environment, the strengths and weaknesses of the program and team, and how to strategically respond. Successful behaviors and actions required for each phase of incident response are explored in the book. Straight from NIST 800-61, these actions What You’ll Learn Who This Book Is For Cybersecurity leaders, executives, consultants, and entry-level professionals responsible for executing the incident response plan when something goes wrong
This was a really solid primer about incident response and covers the basic areas that need to be attended to when setting up an IR program. The contents reference back to the NIST documentation making it very easy to expand your knowledge after finishing. I would like to have seen less diagrams, a lot of them didn't need to be there.
Moving forward I have some actionable items to help me build a solid IR process.