An incident response plan says who does what when something goes wrong. Most frameworks, including NIST SP 800-61 and the AWS Security Incident Response Guide, use similar phases: prepare; detect and analyze; contain, eradicate and recover; and learn from the incident. The plan names roles such as incident commander and communications lead, sets severity levels, and lists contacts, including AWS Support and, if you use it, the AWS Security Incident Response service, which can triage findings and connect you with AWS responders.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 3 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.