Hello, my name is James Youngblood, and in this module, Defensible Security Architecture, we're gonna be talking about responding to breaches. And in this particular lesson, I wanna talk about the incident response team. What is the incident response team? Well simply put, an incident response team is a group of people who prepare for and respond to any emergency incident, such as a natural disaster or an interruption of business operations. Each member will have a very specific role or function. The size and scope of the incident will determine how many and which members of the response team will actually need to respond. Some members of the response team will be volunteers, but the key is to have trained personnel to respond to the incident. So what does an incident response team actually do? Well, an incident response team is going to analyze information obtained from an investigation or a test, and it shares this information with those in critical roles within the company. When there isn't an incident to respond to, the team should meet quarterly to review current response procedures and update them as needed. The more information provided to senior management the better. Now let me stop for just a moment there and kinda explain to you what I'm talking about. What an incident response team is actually going to do is, whenever we have some kind of an incident that is going to disrupt our business. And this doesn't necessarily mean a natural disaster, but a natural disaster could be one of things that we're dealing with. It could be a security breach. It could be a piece of equipment that has failed, or a chemical spill. Whatever is the issue though, we are gonna have members of our incident response team actually respond to that incident and they will handle the situation. Once again, depending upon how large of an incident that we're dealing with, such as a natural disaster, will require us to have many, many more folks actually responding versus say, a piece of equipment that has failed where we may only need just two or three people responding. But the point is, we have people that are designated to respond to specific types of incidents. So what do they do? I'm gonna continue this by saying the incident response team should have a thorough understanding of the critical systems, equipment and personnel for a company, and the incident response team should have a response plan in place to address most types of incidents. There's obviously gonna be incidents that happened that there is no way to plan for these. But for the most common types of incidents, we should have some kinda response readily available and we should have a team that is ready to put that plan into place. Now, the incident response team should be able to be flexible in the responses dependent upon the actual incident. The incident response team should also have the authority to put into place the procedures to help restore the company back to full operations. And the incident response team should have specialists from each department who are trained to handle most types of incidents. As an example, maintenance member responding to a chemical spill, or a member of the IT staff responding to a network breach. My question is, what is the role of IT when we're talking about the incident response team? In the case of a breach in network security, the IT staff will need to take the lead. That is unless, of course, it's a member of the IT team that's actually suspected to be the one responsible. I throw that in there because that does happen from time to time. But most of the time, we're not gonna be fighting against our own team members. Ideally, when we're dealing with a network breach, you'll have the following roles in your incident response team. You're gonna have a team leader. The team leader is the one that's gonna be coordinating all responses with a focus on minimizing the damage caused. Now, many times the team leader is actually gonna be our IT manager. That's not always the case, but most of the time it is. You're gonna have a lead investigator. So the lead investigator's gonna be the one responsible for collecting evidence to determine how the incident happened. This person may or may not be a member of the IT staff, and I say that because I don't want you to think when we're saying that they're the ones responsible for collecting the evidence. They're not the ones that's actually going out and getting the evidence. They're the one that's gonna be collecting the evidence and putting it together in a way that we can actually present that information to senior management. You're gonna need a spokesperson. The spokesperson is gonna be the one responsible for communications from the response team both inside and outside the company. We're also gonna have a member of the legal team as part of our incident response team. Now, typically this particular role is handled by the company's lawyers. Keep in mind that some breaches and other incidents can result in criminal charges, so we do need a member of our legal team being accounted for and being represented on the incident response team. Now I wanna discuss another member of our team, and that's the volunteers. Volunteers are a great resource for an incident response team. They can used to do a lot of the leg work for the lead investigator. But volunteers must be closely watched. Remember that volunteers are not trained. They simply want to help. They should not be given critical roles in the incident response unless it's absolutely necessary. This is what we're gonna be looking at when we're talking about the actual incident response team. Once again, we've talked about who the incident response team is and what their responsibilities are. Join me in my next video as we talk about being prepared to respond. We're actually talking about disaster recovery's role in responding to a breach. Thank you for watching.