Intelligence-Driven Incident Response¶
Roberts, S. J., & Brown, R. (2017). Intelligence-Driven Incident Response: Outwitting the Adversary. O'Reilly.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Decision Cycle Subordination
- In cybersecurity, detect-contain-eradicate cycles run one step behind attacker moves, and tempo is reset through intelligence consolidation and architectural change rather than faster incident response.
This sourceApplies the OODA loop to cyber defense — the defender's detect-contain-eradicate loop runs behind the attacker's, and the remedy is active defense and intelligence consolidation to slow the attacker's tempo and speed the defender's, not faster ticket-closing.
- In cybersecurity, detect-contain-eradicate cycles run one step behind attacker moves, and tempo is reset through intelligence consolidation and architectural change rather than faster incident response.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:9fda4ac5519a · see in the full table