Procedures and Best Practices
Imagine you have just taken over the manager position for your organizationâ€™s incident response team, after coming from another division in the company. Your first realization is that proper procedures, best practices, andÂ sound technologies are not being utilized. You decide to revamp the teamâ€™s efforts. Write a two to three (2-3) page paper in which you: Explicate the main efforts that would be included in the incident response efforts, including but not limited to personnelÂ and team structure, tools and utilities, and proper procedures. Discuss in detail the role that an IDS / IPS would play in the IR efforts, and explain how these systems can assist in the event notification, determination, and escalation processes. ExplainÂ how the NIST SP800-61, Rev. 1 could assist the personnel in classifying incidents so each is identified appropriately and the proper incident-handling procedures are taken. Explain how the use of log management systems (e.g., Splunk) could be a legitimateÂ and useful component of the IR efforts, and describe the potential issues that could arise if not utilized.
Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources