🚨 Incident response - cyber incident management (IR)
Six topics on cyber incident response - from event to study - by international practice (NIST SP 800-61, SANS PICERL, ISO/IEC 27035, ENISA). Time limits and examples are illustrative, intended for training.
Basic concept and roles
Event → warning → incident → violation
Application
Common language: when an event becomes an incident and who does what. Clear roles and escalation reduce chaos response in the first minutes.
Reference
NIST SP 800-61 Rev. 2 · ISO/IEC 27035-1:2023 · ENISA "Good Practice Guide for Incident Management.".
Safety Note
Command and contacts shall be coordinated BEFORE incident. The plan, which is first read during an incident, is too late - preparedness is the first step of the cycle.
Response Life Cycle
NIST SP 800-61, SANS PICERL and ISO/IEC 27035
Choose one frame and stick to it - mixing terms during various incidents creates confusion. Main: the cycle is continuous, not unique.
Application
Structures the response stages to keep steps under pressure. One cycle fits both a technical team and management reports.
Reference
NIST SP 800-61 Rev. 2 · SANS Incident Handler's Handbook (PICERL) · ISO/IEC 27035-1:2023 · NIST CSF 2.0 (Respond, Recover).
Safety Note
The most common error - skip the post incident phase. Without training and prevention of the cause, the same incident recurs; the cycle remains unfinished.
Discovery, triage and classification
Signal to Priority - Levels of gravity
Number of levels (SEV-1...4 or P1...P4) and thresholds must be aligned with the organisation. The main thing is a single, predefined scale, which everyone understands in the same way.
Application
Triage screening noise and giving priority. The severity level determines how quickly to react, what to escalate and whether to start a reporting watch.
Reference
NIST SP 800-61 Rev. 2 · ENISA Reference Incident Classification Toxonomy · MITRE ATT&CK (technical mapping).
Safety Note
Do not underestimate the severity to avoid reporting - some deadlines start from the moment the incident is detected. Reclassification if volume increases.
Active response
Restriction → Eliminating → Restoring
Application
A clear sequence of actions in crisis: first stop, then clear, then restore. For each step - pre-prepared playbook for a particular incident type.
Reference
NIST SP 800-61 Rev. 2 · ISO/IEC 27035-3:2020 (operations) · RFC 3227 (evidence collection) · SANS PICERL (Contain/Eradicate/Recover).
Safety Note
The quick "cleaning" leaves the attacker elsewhere in the system before the volume is cleared. First understand the full presence, then eliminate everything at once.
Legal reporting
Reporting deadlines - NIS2, GDPR and CERT.LV
The specific time limits and addressees depend on the type of entity and jurisdiction - this is a general scheme. Verification of the exact requirements in regulatory enactments and by CERT.LV.
Application
A clear maturity scheme helps not to miss legal windows. Reporting decisions and contacts include playbook - during the crisis there is no time to search.
Reference
NIS2 Directive (EU) 2022/2555 Article 23 · Article 33/34 of GDPR · MK Regulation No 397 · CERT.LV reporting procedures.
Safety Note
NIS2 and GDPR have separate responsibilities - one incident may require both reports to different authorities. The time limit shall begin to run from awareness, or from the end of the full investigation.
Standard map and metrics
Frames, taxonomies and response metrics
Application
Helps to assemble a full IR programme: process (NIST/SANS/ISO), taxonomy (ENISA/ATT&CK), compliance (NIS2/GDPR) and measurement (MTTD/MTTR).
Reference
NIST SP 800-61/86 · ISO/IEC 27035 · ENISA RICT · MITRE ATT&CK · VERIS · FIRST · NIS2 · MK Regulation No 397 · GDPR · TLP 2.0.
Safety Note
Metrics lead upgrades, but may mislead: "fast closing time" with incomplete eradication is a bad sign. View metrics along with the quality of training.
Abbreviations
All abbreviations used in the guide (original and meaning).
- IR
- Incident Response.
- CSIRT
- Computer Security Incident Response Team.
- CERT
- Computer Emergency Response Team.
- CERT.LV
- Latvian national cyber security incident prevention team.
- SOC
- Security Operations Center, Security Operations Center.
- SIEM
- Security Information and Event Management management management.
- EDR / XDR
- Endpoint/Extended Detection and Response.
- IDS / IPS
- Intrusion Detection / Prevention System √ Detection/Prevention.
- IOC
- Indicator of Compromise √ Compromise indicator.
- DFIR
- Digital Forensics and Incident Response.
- RCA
- Root Cause Analysis.
- CIA
- Confidentiality, integrity, accessibility.
- C2
- Command and Control, an attacker's control channel.
- SEV / P
- Severity/Priority level (SEV-1...4).
- NIST SP
- NIST Special Publication, published by the US Standards Institute.
- PICERL
- Prepare, Identify, Container, Eradicate, Recover, Lessons Leaded (SANS).
- CSF
- Cybersecurity Framework √ NIST cybersecurity framework (2.0).
- MTTD
- Mean Time To Detect the average opening time.
- MTTA
- Mean Time To Acknowledgment.
- MTTR
- Mean Time To Reply/Recover .
- RTO
- Recovery Time Objective.
- RPO
- Recovery Point Objective The permissible amount of data loss.
- BCP / DRP
- Business Continuity / Disaster Recovery Plan.
- NIS2
- Network and Information Security Directive 2.
- GDPR
- General Data Protection Regulation (GDPR).
- DVI
- Data State Inspectorate (LV Data Protection Supervisor).
- MK 397
- Cabinet Regulations No. 397 (Implementation of CIS2 in Latvia).
- ENISA
- European Union Agency for Cyber Security.
- RICT
- ENISA Reference Incident Classification Toxonomy.
- VERIS
- Vocabulary for Event Recording and Incident Sharing (Verizon).
- ATT&CK
- MITRE opponent tactics and technical knowledge base.
- FIRST
- Forum of Incident Response and Security Teams.
- DORA
- The Digital Operational Resilience Act.
- PCI DSS
- Payment Card Industry Data Security Standard.
- TLP
- Traffic Light Protocol Information sharing label (2.0).
- STIX / TAXII
- standards for description and exchange of threat intelligence.
- MISP
- Malware Information Sharing Platform - threat exchange platform.