Computer Security Incident Handling Guide¶
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer Security Incident Handling Guide.
Cited by¶
6 citations across 6 artifacts.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Escalation Dominance
- In cybersecurity, incident-response playbooks map escalation ladders from notice through deplatform to prosecution.
This sourceSpecifies incident-response procedures and escalation from notification and analysis through containment to coordination with outside parties and law enforcement. DOI resolves to the correct NIST publication.
- In cybersecurity, incident-response playbooks map escalation ladders from notice through deplatform to prosecution.
- Event Lifecycle Phases
- Cybersecurity: hardening / incident response / post-incident review, where pre-event work is invisible until it pays off, the response is high-tempo and visible, and the post-event phase is where organisational learning happens or fails to.
This sourceDefines the incident-response lifecycle — preparation, detection and analysis, containment/eradication/recovery, and post-incident activity — the cybersecurity hardening/response/review trichotomy.
- Cybersecurity: hardening / incident response / post-incident review, where pre-event work is invisible until it pays off, the response is high-tempo and visible, and the post-event phase is where organisational learning happens or fails to.
- Incident Response
- Cybersecurity incident response: the NIST IR cycle (Detection & Analysis → Containment, Eradication, Recovery → Post-Incident Activity) and the SANS PICERL model carry the skeleton, with containment-before-eradication as the load-bearing inversion — a compromised host is isolated before the attacker is removed.
This sourceThe detection-and-analysis → containment, eradication, recovery → post-incident cycle, with containment-before-eradication and forensic-state preservation as load-bearing moves.
- Cybersecurity incident response: the NIST IR cycle (Detection & Analysis → Containment, Eradication, Recovery → Post-Incident Activity) and the SANS PICERL model carry the skeleton, with containment-before-eradication as the load-bearing inversion — a compromised host is isolated before the attacker is removed.
- Objective Creep
- In cybersecurity, an incident response scoped to contain one intrusion expands to broader threat hunting and architecture redesign during the incident, which becomes harder to close.
This sourceDescribes the containment-eradication-recovery lifecycle in which new information uncovered during containment sends responders back to detection/analysis to re-scope, the source of incident-response scope expansion.
- In cybersecurity, an incident response scoped to contain one intrusion expands to broader threat hunting and architecture redesign during the incident, which becomes harder to close.
Mechanisms¶
- Containment or Rollback Action
- The discipline that guards against this is verifying reversibility before acting, preserving evidence as you go
This sourceDirects incident handlers to preserve evidence during response and treats containment as time for diagnosis.
- The discipline that guards against this is verifying reversibility before acting, preserving evidence as you go
- Critical-Moment Playbook
- When a breach is confirmed at 2 a.m., the team fills the blanks and runs each segment on its own clock, instead of drafting legally sensitive language under pressure.
This sourceRecommends predetermining incident-communication rules, recipients, timing, and legal/public-affairs procedures before an incident so urgent communications can proceed quickly without inventing sensitive policy during response.
- When a breach is confirmed at 2 a.m., the team fills the blanks and runs each segment on its own clock, instead of drafting legally sensitive language under pressure.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:805f9269b277 · see in the full table