Incident Response Lifecycle (NIST SP 800-61)
1. Preparation
Build capability before incidents occur
Build capability before incidents occur
2. Detection & Analysis
Identify and confirm the incident
Identify and confirm the incident
3. Containment
Limit spread and damage
Limit spread and damage
4. Eradication
Remove threat from environment
Remove threat from environment
5. Recovery
Restore normal operations
Restore normal operations
6. Lessons Learned
Post-incident review; improve
Post-incident review; improve
Phase Details
- 1. Preparation
- Develop IR policy, playbooks, communication plan; train the team; configure SIEM/SOAR; establish relationships with legal, HR, law enforcement; conduct tabletop exercises
- 2. Detection & Analysis
- Monitor SIEM alerts, IDS/IPS, EDR; determine scope and severity; classify the incident; notify appropriate stakeholders; begin documenting evidence and timeline
- 3. Containment
-
Short-term: Isolate affected systems (quarantine), block malicious IPs/domains, disable compromised accounts
Long-term: Preserve evidence before fully remedying; consider temporary workarounds to maintain business operations - 4. Eradication
- Remove malware, backdoors, and attacker tools; patch exploited vulnerabilities; reset compromised credentials; confirm no persistence mechanisms remain
- 5. Recovery
- Restore from clean backups; rebuild from known-good images; re-enable services; monitor closely for re-infection; validate system integrity
- 6. Lessons Learned
- Post-incident review (PIR / AAR — After-Action Report): What happened? What worked? What failed? What improvements are needed? Update playbooks accordingly.
Incident Severity Classification
| Level | Description | Example | Response |
|---|---|---|---|
| Critical (P1) | Major breach / business-stopping impact | Ransomware on production systems | Immediate full IR team activation |
| High (P2) | Significant impact; active threat | Compromised admin account; active exfiltration | Same-day response |
| Medium (P3) | Potential breach; suspicious activity | Phishing email opened but no execution | Investigate within 24 hours |
| Low (P4) | Policy violation; minor event | User visiting blocked website | Address in normal workflow |
Communication & Notification
- Internal: IT leadership, legal counsel, HR (if insider threat), executive team, affected business units
- External: Law enforcement (for criminal acts), regulatory bodies (GDPR: 72-hour notification; HIPAA: 60 days), affected customers (if data breach)
- Communication Plan: Pre-defined contacts, escalation paths, and messaging templates — don't improvise during a crisis
- Avoid public disclosure before legal/PR review — premature disclosure can cause stock impact, customer panic, or interfere with law enforcement
Playbooks & Runbooks
- Playbook: Step-by-step response procedure for a specific incident type (ransomware, phishing, DDoS, insider threat)
- Runbook: Operational procedure for a specific technical task (e.g., "How to isolate a host in CrowdStrike")
- Playbooks should be tested via tabletop exercises and updated after each incident
Testing IR Plans
| Exercise Type | Description |
|---|---|
| Tabletop Exercise | Discussion-based; no systems involved; team walks through a scenario verbally |
| Walkthrough | Team reviews the plan step-by-step; verifies documentation accuracy |
| Simulation | Mock incident with realistic artifacts; team responds as if real; limited system involvement |
| Parallel Test | DR site activated alongside primary; both run simultaneously — no production impact |
| Full Interruption Test | Primary site taken offline; DR site takes over; highest realism, highest risk |
| Red Team / Blue Team | Red team attacks (pen test); Blue team defends and detects; Purple team facilitates learning |
Exam Tip: The exam frequently tests the correct order of IR phases. Remember: you must contain before you eradicate. Never begin recovery before eradication — you'll re-infect the restored system. Evidence must be preserved during containment. Lessons Learned is the final phase, not optional.