Security Incident Response vs Incident Detection and Response


How is security incident response different from IDR? When would I use one over the other?

SIR[1] is a new service that helps you prepare for, respond to, and recover from security events, while IDR is designed to help you improve your operations, increase workload resiliency, and accelerate your recovery from critical incidents.

To sum up the above, SIR is used mainly around security events which helps you as an AWS user on managing security events (Prepare, respond, recover) and IDR is to assist operations, resiliency and recovery on incidents which is workload(s) / applications.




answered a month ago

