Incident Response — Quick Reference
NIST IR phases
Severity classification
| Severity | Definition | SLA |
|---|
|---|---|---|
| P1 Critical | Active breach, exfiltration, ransomware | 15 min |
|---|---|---|
| P2 High | Suspicious activity, potential compromise | 1 hour |
| P3 Medium | Policy violation, failed attack attempt | 4 hours |
| P4 Low | Informational, no active threat | 24 hours |
Evidence collection order (critical)
Chain of custody — required fields
Forensic acquisition commands
Containment commands
Playbook quick reference
Ransomware: Identify scope → isolate immediately (pull cable, don't reboot) → do NOT pay without legal/exec decision → assess backup integrity → notify legal/CISO/leadership/regulators as required
Phishing → credential theft: Identify affected accounts → force password reset → revoke sessions/tokens → check for mail-forwarding rules (persistence) → check for attacker-registered MFA devices → audit sent mail
Data breach: What data + how much + exfiltrated or just accessible → determine notification obligations (GDPR 72h, HIPAA 60d, DPDP Act) → preserve all logs under legal hold
Notification timelines by regulation
| Regulation | Jurisdiction | Timeline |
|---|
|---|---|---|
| GDPR | EU | 72 hours to supervisory authority |
|---|---|---|
| HIPAA | US healthcare | 60 days to affected individuals |
| DPDP Act | India | Evolving — Data Protection Board oversight |
Tools by category
| Category | Tools |
|---|
|---|---|
| SIEM | Splunk, Azure Sentinel, Elastic SIEM |
|---|---|
| EDR | CrowdStrike, SentinelOne, Microsoft Defender |
| SOAR | Splunk SOAR, Palo Alto XSOAR |
| Forensics | Volatility (memory), Autopsy (disk), Wireshark (network) |
| Threat intel | VirusTotal, Shodan, AlienVault OTX |

