Your organization is looking to improve its incident response capabilities by implementing security automation. As the security manager, you need to decide which aspect of the incident response process would most benefit from automation. Given the goal to reduce response times and human error, which would be the most effective use of automation?
Automating the entire post-incident report generation without human review.
Automating the initial incident triage to categorize and prioritize incidents based on predefined rules and criteria.
Automating decision-making on how to handle every aspect of the incident response.
Automating communication with the media regarding details of the incident.
|Security Program Management and Oversight
|Threats, Vulnerabilities, and Mitigations
|General Security Concepts