Book Image

Incident Response in the Age of Cloud

By : Dr. Erdal Ozkaya
Book Image

Incident Response in the Age of Cloud

By: Dr. Erdal Ozkaya

Overview of this book

Cybercriminals are always in search of new methods to infiltrate systems. Quickly responding to an incident will help organizations minimize losses, decrease vulnerabilities, and rebuild services and processes. In the wake of the COVID-19 pandemic, with most organizations gravitating towards remote working and cloud computing, this book uses frameworks such as MITRE ATT&CK® and the SANS IR model to assess security risks. The book begins by introducing you to the cybersecurity landscape and explaining why IR matters. You will understand the evolution of IR, current challenges, key metrics, and the composition of an IR team, along with an array of methods and tools used in an effective IR process. You will then learn how to apply these strategies, with discussions on incident alerting, handling, investigation, recovery, and reporting. Further, you will cover governing IR on multiple platforms and sharing cyber threat intelligence and the procedures involved in IR in the cloud. Finally, the book concludes with an “Ask the Experts” chapter wherein industry experts have provided their perspective on diverse topics in the IR sphere. By the end of this book, you should become proficient at building and applying IR strategies pre-emptively and confidently.
Table of Contents (18 chapters)
16
Other Books You May Enjoy
17
Index

Using a well-defined resolution process

Many organizations will experience fast-paced and high-consequence incidents that leave little to no room for error in resolution. Therefore, the IR team has to be well coordinated. Unprepared companies will fail to organize their response teams beforehand. They will make time-wasting moves such as calling for boardroom meetings or a conference meeting with all employees just to restate the obvious. Their response teams will also start allocating responsibilities late in the attack. Hence, their resolution will take much longer and will be inefficient.

Therefore, the IR plan should be well defined according to the advice laid out in this book to guide the team's efforts appropriately when moving fast to contain and recover from a security event. It should have clear roles and responsibilities for the whole team to avoid confusion that might arise. One of the best ways to systematize efforts in IR is to have three tiers of roles. In...