🚨 Incident response - cyber incident management (IR)
Six topics on cyber incident response - from event to study - by international practice (NIST SP 800-61, SANS PICERL, ISO/IEC 27035, ENISA). Time limits and examples are illustrative, intended for training.
Basic concept and roles
Event → warning → incident → violation
Application
Common language: when an event becomes an incident and who does what. Clear roles and escalation reduce chaos response in the first minutes.
Reference
NIST SP 800-61 Rev. 2, ISO/IEC 27035-1:2023, ENISA "Good Practice Guide for Incident Management'.
Safety Note
Command and contacts shall be coordinated BEFORE incident. The plan, which is first read during an incident, is too late - preparedness is the first step of the cycle.
Response Life Cycle
NIST SP 800-61, SANS PICERL and ISO/IEC 27035
Choose one frame and stick to it - mixing terms during various incidents creates confusion. Main: the cycle is continuous, not unique.
Application
Structures the response stages to keep steps under pressure. One cycle fits both a technical team and management reports.
Reference
NIST SP 800-61 Rev. 2, SANS Incident Handler's Handbook (PICERL), ISO/IEC 27035-1:2023, NIST CSF 2.0 (Respond, Recover).
Safety Note
The most common error - skip the post incident phase. Without training and prevention of the cause, the same incident recurs; the cycle remains unfinished.
Discovery, triage and classification
Signal to Priority - Levels of gravity
Number of levels (SEV-1...4 or P1...P4) and thresholds must be aligned with the organisation. The main thing is a single, predefined scale, which everyone understands in the same way.
Application
Triage screening noise and giving priority. The severity level determines how quickly to react, what to escalate and whether to start a reporting watch.
Reference
NIST SP 800-61 Rev. 2, ENISA Reference Incident Classification Toxonomy, MITRE ATT&CK (technical mapping).
Safety Note
Do not underestimate the severity to avoid reporting - some deadlines start from the moment the incident is detected. Reclassification if volume increases.
Active response
Restriction → Eliminating → Restoring
Application
A clear sequence of actions in crisis: first stop, then clear, then restore. For each step - pre-prepared playbook for a particular incident type.
Reference
NIST SP 800-61 Rev. 2, ISO/IEC 27035-3:2020 (operations), RFC 3227 (evidence collection), SANS PICERL (Contain/Eradicate/Recover).
Safety Note
The quick "cleaning" leaves the attacker elsewhere in the system before the volume is cleared. First understand the full presence, then eliminate everything at once.
Legal reporting
Reporting deadlines - NIS2, GDPR and CERT.LV
The specific time limits and addressees depend on the type of entity and jurisdiction - this is a general scheme. Verification of the exact requirements in regulatory enactments and by CERT.LV.
Application
A clear maturity scheme helps not to miss legal windows. Reporting decisions and contacts include playbook - during the crisis there is no time to search.
Reference
NIS2 Directive (EU) 2022/2555, Article 33/34 GDPR, binding legislation, CERT.LV reporting procedures.
Safety Note
NIS2 and GDPR have separate responsibilities - one incident may require both reports to different authorities. The time limit shall begin to run from awareness, or from the end of the full investigation.
Standard map and metrics
Frames, taxonomies and response metrics
Application
Helps to assemble a full IR programme: process (NIST/SANS/ISO), taxonomy (ENISA/ATT&CK), compliance (NIS2/GDPR) and measurement (MTTD/MTTR).
Reference
NIST SP 800-61/86, ISO/IEC 27035, ENISARICT, MITRE ATT&CK, VERIS, FIRST, NIS2, Binding Regulations, GDPR, TLP 2.0.
Safety Note
Metrics lead upgrades, but may mislead: "fast closing time" with incomplete eradication is a bad sign. View metrics along with the quality of training.
Abbreviations
All abbreviations used in the guide (original and meaning).
- IR
- Incident Response - incident response.
- CSIRT
- Computer Security Incident Response Team.
- CERT
- Computer Emergency Response Team.
- CERT.LV
- Latvian national cyber security incident prevention team.
- SOC
- Security Operations Center - Security Operations Centre.
- SIEM
- Security Information and Event Management - Security Events Management.
- EDR / XDR
- Endpoint / Extended Detection and Response - terminal equipment and extended detection.
- IDS / IPS
- Intrusion Detection / Prevention System - intrusion detection/prevention.
- IOC
- Indicator of Compromise - a compromise indicator.
- DFIR
- Digital Forensics and Incident Response - digital forensics and response.
- RCA
- Root Cause Analysis - an analysis of the original cause.
- CIA
- Confidentiality, Integrity, Availability - confidentiality, integrity, accessibility.
- C2
- Command and Control - An attacker's control channel.
- SEV / P
- Severity / Priority - severity/priority level (SEV-1...4).
- NIST SP
- NIST Special Publication.
- PICERL
- Prepare, Identify, Container, Eradicate, Recover, Lessons Leaded (SANS).
- CSF
- Cybersecurity Framework - NIST cybersecurity framework (2.0).
- MTTD
- Mean Time To Detection - average opening time.
- MTTA
- Mean Time To Acknowedge - mean time for response (confirmation).
- MTTR
- Mean Time To Reply/Recover - mean resolution/renewal time.
- RTO
- Recovery Time Objective - permissible renewal time.
- RPO
- Recovery Point Objective - allowable amount of data loss.
- BCP / DRP
- Business Continuity / Disaster Recovery Plan.
- NIS2
- Network and Information Security Directive 2.
- GDPR
- General Data Protection Regulation - General Data Protection Regulation.
- DVI
- Data State Inspectorate (LV Data Protection Supervisor).
- saistošie normatīvie akti
- Cabinet Regulations No. 397 (Implementation of CIS2 in Latvia).
- ENISA
- European Union Agency for Cyber Security.
- RICT
- ENISA Reference Incident Classification Toxonomy.
- VERIS
- Vocabulary for Event Recording and Incident Sharing (Verizon).
- ATT&CK
- MITRE opponent tactics and technical knowledge base.
- FIRST
- Forum of Incident Response and Security Teams.
- DORA
- Digital Operational Resilience Act - EU financial sector resilience regulation.
- PCI DSS
- Payment Card Industry Data Security Standard.
- TLP
- Traffic Light Protocol - Information sharing label (2.0).
- STIX / TAXII
- standards for description and exchange of threat intelligence.
- MISP
- Malware Information Sharing Platform - threat exchange platform.