Security Incident Response
Security incident response is the coordinated work of detecting, containing, analyzing, and recovering from a cybersecurity incident. It connects technical investigation with business decisions, communication, evidence handling, and improvements that reduce future impact.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Security Incident Response
A security incident is not an elaborate race to type faster than the attacker. It is coordinated work for limiting harm and returning systems, data, and operations to a state that deserves trust. That last word carries more weight than a green health check, which is frequently very pleased with itself and sometimes wrong.
The useful shape is a loop. Prepare roles, authority, contact paths, evidence practices, and recovery priorities before the alarm arrives. Then treat the alert as a clue, not a verdict. An observation records something the system showed. A hypothesis explains it. A decision says what happens next and why. Keeping those three apart prevents an anxious guess from acquiring the dignity of a fact merely because it appeared in a chat window.
The central job is to build a shared picture of scope and impact. Scope is what the incident touched: identities, assets, data, services, and activity. Impact is what it did to the organization. They are cousins, not twins. A large scan can touch much and hurt little. One privileged identity can touch very little and create a thoroughly unwelcome afternoon.
Containment is therefore a trade. Isolating a host can stop communication and interrupt a critical service. Disabling an account can stop access and stop someone's legitimate work. Choose an authorized action with a stated objective, a sign that it worked, and a rollback path. Preserve evidence while this happens; volatile information has the inconvenient habit of leaving before the meeting agenda is complete.
After that come eradication and recovery. Remove the cause and persistence, restore from trusted sources, validate controls and business function, and keep monitoring active. Availability alone is not the finish line. A recovered service needs to be trustworthy, not merely capable of answering a cheerful ping.
Incident response reaches beyond the security operations center. The incident commander aligns technical responders, system owners, leadership, legal and privacy specialists, communications, and external partners around priorities and updates. When recovery ends, turn the record into corrective actions with owners, dates, and verification. Otherwise the same problem has been granted a season renewal.
Read the slides for the response loop and containment tradeoffs. Use the cheatsheet when you need the triage record, status-update shape, recovery gate, or role map. Then take the quiz to test whether scope, impact, evidence, and recovery have stopped impersonating one another.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.nist.gov/publications/incident-response-recommendations-and-considerations-cybersecurity-risk-management-csf
Supports
- Incident response integrated throughout Cybersecurity Framework 2.0 risk management
- Preparation, reduction of incident impact, and improvement of detection, response, and recovery
- Common language for internal and external incident response communication
- Current publication identity and April 2025 release
- https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r3.pdf
Supports
- Incident response roles for leadership, handlers, technology professionals, legal, privacy, and public affairs
- Analysis, prioritization, mitigation, root-cause work, restoration, and resilience improvement
- Incident response recommendations across Govern, Identify, Protect, Detect, Respond, and Recover
- Coordination, information sharing, evidence, recovery, and continuous improvement considerations
- Iterative response activities under incomplete information
- https://www.cisa.gov/topics/cybersecurity-best-practices/executive-order-improving-nations-cybersecurity
Supports
- Standardized procedures for identifying, coordinating, remediating, recovering, and tracking mitigations
- Shared practices for coordinated communication, analysis, discovery, and response
- Usefulness of the federal playbook's broader practices outside federal agencies
- https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
Supports
- Operational incident response phases, checklists, action tracking, and coordination
- Preparation, detection and analysis, containment, eradication, recovery, and post-incident activities
- Incident documentation, evidence preservation, communications, remediation, and closure
- https://www.cisa.gov/sites/default/files/2023-01/8_-_ctep_aar-ip_template_2020_final_508.pdf
Supports
- Discussion-based tabletop exercises with defined scope, scenario modules, objectives, and improvement planning
- https://insights.sei.cmu.edu/history-of-innovation/fostering-growth-in-professional-cyber-incident-management/
Supports
- Formation of the CERT Coordination Center after the 1988 Morris Worm
- Growth of coordinated computer security incident response teams
- https://www.first.org/about/history
Supports
- Formation of FIRST in 1990 after uncoordinated responses caused duplicated effort and conflicting solutions
- https://www.nist.gov/publications/establishing-computer-security-incident-response-capability-csirc
Supports
- NIST SP 800-3 publication in November 1991 and its centralized incident response capability model
- https://csrc.nist.gov/nist-cyber-history/risk-management/chapter
Supports
- January 2004 publication of NIST SP 800-61 and the documented incident response guide sequence
- https://www.nist.gov/publications/computer-security-incident-handling-guide
Supports
- March 2008 SP 800-61 Revision 1 as the predecessor to Revision 2
- August 2012 publication of SP 800-61 Revision 2 and its preparation-through-lessons-learned coverage
- https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10
Supports
- February 2014 release of Cybersecurity Framework 1.0 and its Identify, Protect, Detect, Respond, and Recover functions
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
Supports
- February 2024 release of Cybersecurity Framework 2.0 and the addition of Govern
- https://sre.google/sre-book/managing-incidents/
Supports
- Living incident state documents, explicit command handoff, and a recognized coordination post
- https://sre.google/workbook/postmortem-culture/
Supports
- Action-item ownership, timely postmortems, operational data capture, and organizational learning
- https://www.splunk.com/en_us/products/splunk-enterprise-security-features.html
Supports
- Analyst queue, investigation, case management, threat topology, response plans, and automation capabilities
- https://learn.microsoft.com/en-us/azure/sentinel/automation/automation
Supports
- Incident handling automation rules, playbooks, triage tasks, investigation support, and response automation
- https://cloud.google.com/security/products/security-operations/investigate
Supports
- Case management, investigation workbench, entity context, alert grouping, and response playbooks
- https://www.paloaltonetworks.com/resources/ebooks/cortex-xsiam
Supports
- Incident timelines, alert enrichment, inline playbooks, endpoint remediation, and investigation context
- https://www.servicenow.com/docs/r/security-management/security-incident-response/sir-landing-page.html
Supports
- Security incident tracking from analysis through containment, eradication, recovery, review, and closure
- https://www.atlassian.com/software/jira/service-management/product-guide/getting-started/incident-management
Supports
- Incident coordination, affected-service context, responders, communication, and post-incident review workflow
