"Playbooks" page

A playbook is a sequence of steps written in advance: "if such a thing happens, do this, then that". You write it calmly, once, and afterwards it runs in one click, with no need to think under pressure.

The ready-made steps: four situations, and what to do in each.

Five families

FamilyWhat goes in it
NetworkSet an address aside, cut a link.
EndpointIsolate a machine from the rest of the network.
AccountSuspend an account, force a password change.
ForensicsGather the traces to understand afterwards.
CustomWhatever you wrote for your own way of working.

What a step does

Each playbook is a list of readable steps: send a notification by message or email, trigger an automatic response on a machine, open an incident file, or simply wait. Nothing mysterious: you read the list before running it.

Nothing goes off by itself. A playbook is triggered by a button, on a machine you choose. You see its steps beforehand, and the "History" tab shows afterwards what was done, when, and how long it took.

Should they be used every day?

No. At Les Ateliers, no playbook has been triggered since installation, and that is quite as it should be. They are there like the fire extinguisher on the wall: you are glad it exists, you hope never to use it.

The most useful one for a small company is the simplest: "tell everybody". Two steps, one message, and the certainty that nobody will hear the news three days later.

In closing

A playbook is written in calm so it can run under pressure. That is its whole point: on the day it is needed, nobody has to think or remember the order of the steps.

Rating
0 0

Commenting is not enabled on this course.