What's changed: Initial version
5.2Incident response based on NIST SP800-61
Covers the elements an incident response (IR) plan should contain and the NIST SP800-61 lifecycle (preparation / detection and analysis / containment, eradication, and recovery / post-incident activity), so you can map "which phase this event is in and what to do next."
Incident response descends into chaos usually because "which phase we are in and who does what next" is not shared. NIST SP800-61 systematizes this response as a four-phase lifecycle, providing a common language for when you are unsure. This section covers both the contents of the IR plan prepared in advance and the judgment of mapping an ongoing event to a phase to choose the next move. Even field tensions like "preserve evidence first or stop it first" become tractable once you understand the phases.
5.2.1Elements of an IR plan
- NIST SP800-61 lists elements an incident response plan should contain: mission, strategies and goals, senior management approval, the organizational approach to IR, communication between the IR team and the rest of the organization, metrics to measure maturity, a roadmap for maturing the program, and how the program fits into the overall organization. It matters that the plan is approved as a document and backed by authority.
- A plan, a procedure, and a policy are distinct: the policy states the "what should be done" principles, the plan provides the structure and big picture, and the procedure (playbook) gives the concrete steps of "who runs which commands for this event." The SOC can act without hesitation precisely because these three layers are prepared in advance.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

