Preparation

Preparation is the foundational phase of the defensive lifecycle, carried out before any incident occurs. Everything that follows, detection, response, recovery, and post-incident learning, is more effective when the groundwork is solid. Preparation reduces the attack surface, builds visibility, and ensures that teams, tools, and processes are ready when they are needed. It is ongoing work rather than a one-time project, because environments and threats change constantly.

This pillar covers the practices that build and maintain readiness.

  • Asset management keeps an accurate inventory of systems, software, and data so defenders know what they are protecting.
  • Change management controls how systems are modified so that changes do not introduce unmanaged risk.
  • Hardening reduces the attack surface by configuring systems securely and removing unnecessary exposure.
  • Patch management applies updates in a timely, tested way to close known weaknesses.
  • Testing and exercises validate defenses and practice response through drills, tabletop exercises, and simulations.
  • Threat intelligence integration feeds knowledge of adversaries and techniques into defensive decisions.
  • Vulnerability management continuously finds, prioritizes, and remediates weaknesses across the environment.

References#

  • NIST SP 800-61, Computer Security Incident Handling Guide
  • NIST SP 800-40, Guide to Enterprise Patch Management Planning
  • SANS Institute, security operations resources

Cookie Consent

We use cookies to enhance your experience. Learn more