Any good attacker will tell you that expensive security monitoring & prevention tools aren't enough to keep you secure This practical book demonstrates a data-centric approach to distilling complex security monitoring incident response & threat analysis ideas into their most basic elements You'll learn how to develop your own threat intelligence & incident detection strategy rather than depend on security tools alone Written by members of Cisco's Computer Security Incident Response Team this book shows IT & information security professionals how to create an Info Sec playbook by developing strategy technique & architecture Learn incident response fundamentals-and the importance of getting back to basics Understand threats you face & what you should be protecting Collect mine organize & analyze as many relevant data sources as possible Build your own playbook of repeatable methods for security monitoring & response Learn how to put your plan into action & keep it running smoothly Select the right monitoring & detection tools for your environment Develop queries to help you sort through data & create valuable reports Know what actions to take during the incident response phase