Expert Operational six-phase methodology that prioritizes decision velocity, regulatory timing, and defensible records.
1. Assemble Team
2. Detect & Ascertain
3. Contain & Recover
4. Assess Damage & Severity
5. Begin Notifications
6. After-Action Review
NIST Industry-standard 4-phase incident response framework from NIST Computer Security Incident Handling Guide. Widely adopted across federal agencies, defense contractors, and regulated industries. Includes NIST prioritization matrix.
1. Preparation
2. Detection & Analysis
3. Containment, Eradication & Recovery
4. Post-Incident Activity
ISO 27035 International 5-phase information security incident management standard from ISO/IEC, aligned with ISO 27001 ISMS programs. Best for ISO 27001-certified organizations, EU/EMEA enterprises, and any environment where alignment with international standards is contractually required. Native integration with ISO 27037 evidence handling.
1. Plan and Prepare
2. Detection and Reporting
3. Assessment and Decision
4. Responses
5. Lessons Learned
CISA CISA Federal Government Cybersecurity Incident Response Playbook (Nov 2021, updated 2024) per Executive Order 14028. Mandatory for FCEB agencies, encouraged by CISA for private sector adoption. Aligns with NIST 800-61 Rev. 2 phase model with CISA-specific procedural elements: Major Incident Determination, mandatory CISA notification within 24 hours, MITRE ATT&CK technique enumeration, sector Risk Management Agency coordination, OMB and congressional reporting for Major Incidents, formal After-Action Report submission within 60 days.
1. Preparation
2. Detection & Analysis
3. Containment
4. Eradication & Recovery
5. Post-Incident Activity
SANS SANS PICERL 6-phase incident response model from SEC504 / SEC401 course material. The most widely-taught IR model in practice, often preferred by SANS-trained responders. Phases: Preparation, Identification, Containment (short and long-term), Eradication, Recovery, Lessons Learned. Tightly mapped to MITRE ATT&CK techniques and chain-of-custody preservation patterns from SANS Incident Handler's Handbook.
1. Preparation
2. Identification
3. Containment
4. Eradication
5. Recovery
6. Lessons Learned