Preparation happens before any incident. This phase determines how well you handle future events.
Team and roles:
- Identify who handles incidents
- Define escalation paths
- Establish communication channels
Documentation:
- Written response plan
- Contact lists including vendors
- System inventories and diagrams
- Playbooks for common incidents
Tools: Forensic tools ready. Isolated analysis systems. Backup systems. Administrative access ready.
Training: Run tabletop exercises. Practice scenarios. Review past incidents.