Thursday 12 March 2020

5 Steps to building an Incident Response Plan for a Large Organization

EC-Council Study Materials, EC-Council Guides, EC-Council Learning, EC-Council Exam Prep

Large organizations are encountered continuously by questions like, “Will the data collected be safe?”, “What happens if a breach occurs?”, “What information did they gain access to?”, “Do we have the right skill/plan to protect the organization from being infiltrated?” It is because of these questions that large organizations must have an incident response plan.

Creating an Incident Response Plan for Large Organizations


A strong incident response plan ensures that the organization can handle the attack with efficiency and minimal damage. However, building the plan is not as easy as it seems. Not to worry, we’ve broken it down into five steps that you can follow to draft an incident response plan for a large organization:

Step 1: Prepare

When working with large organizations, start by analyzing the organization’s environment, determine essential services, components, and applications sensitive to maintaining operations in the event of the breach. Identify what data must be protected, understand where and how it is stored, and whether any changes must be made.

Step 2: Build an incident response team

Have a group of skilled professionals on board who are trained and certified to deal with an incident should it arise. The incident response manager will be in charge of ensuring coordination and communication with all different members of the team.

Step 3: Establish a disaster recovery strategy

To ensure business continuity, it is essential that disaster recovery is a part of the incident response plan. This is done to reduce dwell time, thereby reducing potential damage – financial and reputational.

Step 4: Test the plan

Much like how a fire drill is implemented, it is important to test the plan to ensure that you have covered all areas. It is also essential that the cyber forensic team is included in the process to help the incident response team identify areas that need focus.

Step 5: Plan for debriefing

For the last step, consider all the areas that must be improved. Create a report that covers all that was done, including recommendations. Conducting a gap analysis will help you uncover which areas need more focus.

Become an incident handler and help reduce dwelling time


EC-Council’s Certified Incident Handler (ECIH) program is designed in collaboration with cybersecurity and incident handling and response practitioners across the globe. ECIH is a comprehensive specialist-level incident response program that imparts the skills and knowledge organizations need when handling the incident to reduce the impact of both a financial and reputational perspective.

Related Posts

0 comments:

Post a Comment