Skip to content

Commit cf5dfcb

Browse files
authored
Create Create a Security Incident Playbook (#16)
This prompt helps create a structured playbook for handling security incidents in ServiceNow. Define steps for detection, analysis, containment, eradication, and recovery to ensure a consistent and adaptable response process.
1 parent 719f9fa commit cf5dfcb

1 file changed

Lines changed: 15 additions & 0 deletions

File tree

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
Assume the role of a cybersecurity analyst tasked with creating a playbook for managing security incidents in ServiceNow.
2+
The playbook should provide a structured, repeatable process for addressing any type of security incident.
3+
4+
Follow these steps:
5+
6+
1. Detection: Define how to identify and validate a wide range of security incidents, including proper documentation.
7+
2. Analysis: Guide the team through assessing scope, impact, and root cause, using logs and relevant tools.
8+
3. Containment: Outline short-term and long-term strategies to prevent the threat from spreading.
9+
4. Eradication: Provide steps for removing the root cause, such as eliminating malware or securing compromised accounts.
10+
5. Recovery: Describe how to restore affected systems and validate that the environment is secure and operational.
11+
6. Post-Incident Review: Include a process for conducting a review, capturing lessons learned, and identifying improvements for future incidents.
12+
13+
The playbook should provide IT teams with a clear, repeatable process for addressing security incidents in ServiceNow, ensuring minimal downtime and data loss.
14+
The template should be concise, limited to 600 words, clear, and easy to follow for both technical and non-technical users.
15+
It should provide practical examples without delving too deep into technical jargon.

0 commit comments

Comments
 (0)