The document provides guidelines for establishing an effective computer security incident response capability. It recommends that organizations create an incident response policy and plan, develop procedures for incident handling and reporting, select an appropriate incident response team structure, and determine services the team should provide. The document also stresses the importance of preventing incidents through effective security controls and reducing their impact through efficient detection, containment, eradication and recovery procedures. Coordination with external groups is also highlighted as a key part of incident response.