Imagine you have just taken over the manager position for your organization’sincident response team, after coming from another division in the company. Your first realization is that proper procedures, bestpractices, and sound technologies are not being utilized. You decide to revamp the team’s efforts.
Write a two to three (2-3) page paper in which you:
the main efforts that would be included in the incident response
efforts, including but not limited to personnel and team structure,
tools and utilities, and proper procedures.
in detail the role that an IDS / IPS would play in the IR efforts, and
explain how these systems can assist in the event notification,
determination, and escalation processes.
how the NIST SP800-61, Rev. 1 could assist the personnel in classifying
incidents so each is identified appropriately and the proper
incident-handling procedures are taken.
- Explain how the use of log management systems (e.g., Splunk)
could be a legitimate and useful component of the IR efforts, and
describe the potential issues that could arise if not utilized.5.Use at
least three (3) quality resources in this assignment. Note: Wikipedia
and similar Websites do not qualify as quality resources.
Your assignment must follow these formatting requirements:
typed, double spaced, using Times New Roman font (size 12), with
one-inch margins on all sides; citations and references must follow SWS
or school-specific format. Check with your professor for any additional
a cover page containing the title of the assignment, the student’s
name, the professor’s name, the course title, and the date. The cover
page and the reference page are not included in the required assignment
The specific course learning outcomes associated with this assignment are:
- Summarize the various types of disasters, response and recovery methods.
- Describe detection and decision-making capabilities in incident response.