Incident Response Foundations: NIST, PICERL & Team Roles
Incident response is the discipline of taking a confirmed security incident from first confirmation through full recovery and a formal lessons-learned review. This chapter lays the groundwork, the frameworks, the classification system, and the team roles, that the remaining seven chapters in this module build on directly.
SOC Incident Handling vs Full Incident Response
SOC Operations and Incident Response cover different slices of the same incident. Knowing where one ends and the other begins avoids duplicated work and dropped handoffs.
| Dimension | SOC-Scoped Incident Handling | Full Incident Response Ownership |
|---|---|---|
| Covered in | SOC Operations module, Chapter 5 (Incident Handling Workflow) | This module, all 8 chapters |
| Scope | Confirm the alert is a real incident, apply initial containment, open a case | Own the incident end-to-end through post-incident review |
| Ends when | Handoff to IR, or closure of a minor incident fully resolved at SOC level | The incident is closed, documented, and lessons learned are captured |
| Typical owner | L1/L2 SOC analyst | Incident Commander and a cross-functional IR team |
| Depth of investigation | Enough to confirm and contain | Full scoping, root cause, evidence handling, chain of custody |
Two Frameworks: NIST 800-61 vs SANS PICERL
Two frameworks describe the same underlying work at different levels of granularity. Most IR teams reference both.
| NIST SP 800-61 Phase | Maps to SANS PICERL Phase(s) | Notes |
|---|---|---|
| Preparation | Preparation | Same scope in both: policies, tooling, training, and playbooks built before an incident happens |
| Detection and Analysis | Identification | Confirming and scoping that an incident is real |
| Containment, Eradication, and Recovery | Containment, Eradication, Recovery | NIST combines three PICERL phases into one; the underlying work is identical |
| Post-Incident Activity | Lessons Learned | A formal review after the incident is closed |
The remaining chapters in this module are structured around PICERL's six steps, since each maps to one chapter.
Incident Classification and Severity
Every incident gets sorted along two axes: what kind of incident it is, and how bad it is. Both drive who gets paged and how fast.
Common Incident Categories
| Category | Description |
|---|---|
| Malware / Ransomware | Malicious code executes on a system, encrypting or destroying data or giving an attacker persistent access |
| Unauthorized Access | An actor gains access to a system or account without authorization, often via stolen or misused credentials |
| Data Breach / Exfiltration | Sensitive data is accessed, copied, or removed by an unauthorized party |
| Denial of Service | An attack degrades or disables the availability of a system or service |
| Insider Threat | A current or former employee, contractor, or partner misuses legitimate access to cause harm |
| Phishing / BEC | An attacker uses deceptive email or messaging to steal credentials, deliver malware, or redirect payments |
Severity Levels
- Critical: active ransomware encrypting production systems, or confirmed exfiltration of regulated data.
- High: confirmed unauthorized access to a sensitive system with containment not yet applied.
- Medium: contained malware limited to a single non-critical endpoint.
- Low: an isolated phishing email reported and blocked before any user interaction.
The IR Team: Roles and Structure
Full incident response is a team function, not a solo one. A working IR team spans technical, communications, legal, and business roles.
| Role | Responsibility |
|---|---|
| Incident Commander / IR Manager | Owns the incident end-to-end and makes the final call on every major decision |
| Lead Investigator / Forensic Analyst | Runs the technical investigation: scope, root cause, and evidence collection |
| Communications Lead | Manages internal updates and external, customer, or regulator communication |
| Legal / Compliance Liaison | Advises on breach notification obligations, privilege, and regulatory exposure |
| IT / Infrastructure Support | Executes containment, eradication, and recovery actions on affected systems |
| Executive Sponsor | Provides authority and resourcing, and makes business-risk decisions above the IC's authority |
How the Rest of This Module Builds on This Chapter
This chapter set the frame. The next seven chapters walk PICERL's phases in order, then close with a chapter on scenarios that don't follow the standard playbook cleanly.
- Preparation: IR plans, playbooks, and tabletop exercises built before an incident hits.
- Detection and Analysis: scoping an incident, handling evidence, chain of custody, and building a timeline.
- Containment Strategy: how to decide what to isolate, and when.
- Eradication: removing the threat for good, not just the symptom.
- Recovery: phased restoration back to normal operations.
- Post-Incident Activity: lessons learned, metrics, and disclosure obligations.
- Specialized IR Scenarios: ransomware, BEC, insider threat, and cloud incidents.
Key Takeaways
- NIST SP 800-61 uses 4 phases; SANS PICERL uses 6 phases that map cleanly onto it, with Containment, Eradication, and Recovery collapsing into one NIST phase.
- PICERL's 6 phases, Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned, structure the rest of this module.
- Incidents are classified by category (malware, unauthorized access, data breach, DoS, insider threat, phishing/BEC) and rated by severity to drive prioritization.
- A functioning IR team spans technical, communications, legal, infrastructure, and executive roles, not just investigators.
- SOC-scoped incident handling confirms and contains; full IR ownership carries the incident through post-incident review, and this module starts where SOC-scoped handling stops.
- CSIRT, CERT, and PSIRT are related but distinct terms for an incident response function.
Knowledge Check
Click an answer to reveal the explanation.
Which single NIST SP 800-61 phase covers the same ground as PICERL's Containment, Eradication, and Recovery phases combined?
An L2 SOC analyst confirms a phishing email led to a compromised account and disables it as initial containment. At what point does this typically move from SOC-scoped handling into full incident response ownership?
A breach investigation confirms exposure of regulated customer data. Who is primarily responsible for advising on breach notification obligations?