Response

Response is the phase of the defensive lifecycle where an organization acts on a confirmed incident to limit damage and regain control. It follows detection, which raises the signal, and precedes recovery, which restores normal operations. Effective response is fast, methodical, and well coordinated, balancing the need to stop an attacker against the need to preserve evidence and keep the business running. The quality of a response often depends on how well the preparation phase equipped the team with plans, access, and practiced roles.

This pillar covers the activities that take place during an active incident.

  • Triage assesses incoming alerts and reports to confirm whether an incident is real and how urgent it is.
  • Investigation determines the scope, entry point, and impact of the incident by examining affected systems and evidence.
  • Containment stops the incident from spreading further while the team works toward a full fix.
  • Eradication removes the adversary's presence, including malware, footholds, and unauthorized access.
  • Communication keeps stakeholders, leadership, and affected parties informed with accurate and timely updates.
  • Coordination aligns the people, teams, and tasks so the response moves in a single direction.

References#

  • NIST SP 800-61, Computer Security Incident Handling Guide
  • SANS Institute, Incident Handler's Handbook

Cookie Consent

We use cookies to enhance your experience. Learn more