From the course: Complete Guide to Cybersecurity: A Practical Approach
Unlock this course with a free trial
Join today to access over 24,400 courses taught by industry experts.
Defining playbooks and run book automation (RBA)
From the course: Complete Guide to Cybersecurity: A Practical Approach
Defining playbooks and run book automation (RBA)
- [Instructor] Playbooks and Run book automation have emerged as very valuable tools to streamline incident response, minimize human error, and enhance the overall efficiency of cybersecurity teams. Now here we're going to explore the benefits of incorporating Playbooks and Run Book automation in incident response and offer a practical guidance on the implementation of those artifacts. At the end of the day, incident response Playbooks are detailed step-by-step guides that outline the procedures and best practices that you should follow when managing and mitigating specific types of cybersecurity incidents. Playbooks enable security teams to act quickly and confidently and minimize the time that it takes to identify, contain, and remediate incidents. They can also serve as an essential resource for training new team members and disseminating best practices across your organization. Earlier we talked about the importance of documenting lessons learned. While updating Playbooks is a…
Contents
-
-
-
-
-
-
-
-
-
-
-
(Locked)
Module 2: Incident response, digital forensics, and threat hunting introduction39s
-
(Locked)
Learning objectives54s
-
(Locked)
Exploring how to get started in incident response6m 6s
-
(Locked)
Understanding the incident response process5m 46s
-
(Locked)
Defining playbooks and run book automation (RBA)10m 29s
-
(Locked)
Understanding cyber threat intelligence (CTI)10m 23s
-
(Locked)
Understanding data normalization3m 1s
-
(Locked)
Deconstructing universal data formats and 5-tuple correlation1m 19s
-
(Locked)
Understanding security monitoring fundamentals6m 32s
-
(Locked)
Surveying security monitoring tools13m 33s
-
(Locked)
-
-
-
-
-
-
-
-
-
-
-
-
-
-