Summary of preparation items
Thorough preparation for responding to security events is critical for timely and effective incident response. Incident response preparation involves people, processes, and technology. All three of these domains are equally important to preparation. You should prepare and evolve your incident response program across all three domains.
Table 2 summarizes the preparation items detailed in this section.
Table 2 – Incident response preparation items
Domain | Preparation item | Action items |
---|---|---|
People | Define roles and responsibilities. |
|
People | Train incident response staff on AWS. |
|
People | Understand AWS support options. |
|
Process | Develop an incident response plan. |
|
Process | Document and centralize architecture diagrams. |
|
Process | Develop incident response playbooks. |
|
Process | Run regular simulations. |
|
Technology | Develop AWS account structure. |
|
Technology | Develop and implement a tagging strategy that helps responders to identify ownership and context for findings. |
|
Technology | Update AWS account contact information. |
|
Technology | Prepare access to AWS accounts. |
|
Technology | Understand threat landscape. |
|
Technology | Select and set up logs. |
|
Technology | Develop forensics capabilities. |
|
An iterative approach is recommended for incident response preparation. All of these preparation items cannot be done overnight; you should create a plan to start small and continuously improve your incident response capabilities over time.