Preparing your Incident Response Plan
No two incident response plans are alike. What your plan looks like will depend on many variables, from the size of the company, the scope of business, regulatory needs, to the company culture.
No two incident response plans are alike. What your plan looks like will depend on many variables, from the size of the company, the scope of business, regulatory needs, to the company culture.
You already know you need an incident-response plan. But what should it look like? What’s involved in creating such a plan? I’ll help you get started.
In the post “The Basics of Controls,” you read about different types of controls. Before you can do anything with all that knowledge, you need to understand where you’re going to apply those controls. We apply them, of course, to our environments.
CTRL Center’s Reference Desk offers a region-by-region survey of data-protection laws. Unfortunately, just like everything else relating to cybersecurity, the landscape is constantly changing. Where can you go to make sure you know the very latest legal developments? Read on for some advice.
In the post, “Understanding Vulnerabilities,” I introduced you to my dear friends at MITRE, the NVD, and OWASP. You’ll want to get friendly with those fine organizations, if you want to manage your cybersecurity on your own. You’re going to need them as we move into the next step of this exercise: namely, vulnerability remediation.