Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Incident Response

Prepare the organization to declare, manage, investigate, contain, communicate, recover from, and learn from cybersecurity incidents.

5Guided phases
20CSF outcomes
54Mapped controls
21D3FEND techniques

Incident operations playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Make incident response a coordinated operating capability rather than a document opened after something goes wrong.

Strong response depends on decision rights, evidence, communication, third parties, containment, and recovery criteria that are tested before the crisis.

Built forIncident responders · Security leaders · Legal and communications teams · System owners · Executives
01

Guided phase

Prepare people, plans, and partners

Establish maintained plans, roles, authorities, and third-party coordination before an incident.

Actions to take

  • Define incident command, technical, legal, privacy, communications, and business roles.
  • Maintain contact paths and third-party obligations.
  • Exercise decisions, not just technical procedures.
ID.IM-04Identify · Improvement

Improve Incident Response and Cybersecurity Plans

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

4 controls3 800-171
GV.RR-02Govern · Roles, Responsibilities, and Authorities

Roles, Responsibilities, and Authorities

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

6 controls
GV.SC-08Govern · Cybersecurity Supply Chain Risk Management

Include Suppliers in Incident Activities

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

7 controls4 800-1711 800-172
02

Guided phase

Declare and triage incidents

Use consistent criteria to validate, categorize, prioritize, and begin incident management.

Actions to take

  • Define what constitutes an incident and who can declare one.
  • Create severity and prioritization criteria tied to mission impact.
  • Record assumptions, confidence, and immediate actions.
DE.AE-08Detect · Adverse Event Analysis

Declare Incidents Using Defined Criteria

Incidents are declared when adverse events meet the defined incident criteria

2 controls2 800-1713 800-1723 D3FEND2 mitigations
RS.MA-01Respond · Incident Management

Execute the Incident Response Plan

The incident response plan is executed in coordination with relevant third parties once an incident is declared

5 controls3 800-1711 800-172
03

Guided phase

Manage and communicate

Escalate decisions and keep internal and external stakeholders informed with approved, accurate information.

Actions to take

  • Define escalation triggers and executive decision points.
  • Coordinate legal, regulatory, customer, insurer, supplier, and public communications.
  • Protect sensitive investigative information.
RS.CO-02Respond · Incident Response Reporting and Communication

Notify Stakeholders

Internal and external stakeholders are notified of incidents

5 controls3 800-1714 800-1723 D3FEND2 mitigations
RS.CO-03Respond · Incident Response Reporting and Communication

Share Incident Information

Information is shared with designated internal and external stakeholders

5 controls3 800-1714 800-1723 D3FEND2 mitigations
04

Guided phase

Analyze, contain, and eradicate

Establish facts, preserve evidence, determine scope, contain impact, and remove the cause.

Actions to take

  • Preserve evidence provenance and investigation records.
  • Validate scope across identity, endpoint, network, cloud, and suppliers.
  • Use containment and eradication criteria that account for business impact.
RS.AN-03Respond · Incident Analysis

Establish Incident Facts and Root Cause

Analysis is performed to establish what has taken place during an incident and the root cause of the incident

3 controls2 800-1713 800-1723 D3FEND2 mitigations
RS.AN-06Respond · Incident Analysis

Preserve Investigation Action Records

Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved

3 controls3 800-1713 800-1723 D3FEND2 mitigations
RS.AN-07Respond · Incident Analysis

Preserve Incident Data and Metadata

Incident data and metadata are collected, and their integrity and provenance are preserved

3 controls3 800-1713 800-1723 D3FEND2 mitigations
05

Guided phase

Recover and improve

Transition deliberately into recovery and convert lessons into measurable improvement.

Actions to take

  • Apply recovery initiation criteria and prioritize services.
  • Verify restored assets, monitoring, and business operations.
  • Assign owners and deadlines to lessons learned.
RC.RP-01Recover · Incident Recovery Plan Execution

Execute the Recovery Plan

The recovery portion of the incident response plan is executed once initiated from the incident response process

3 controls2 800-1714 800-1723 D3FEND2 mitigations
RC.RP-02Recover · Incident Recovery Plan Execution

Select and Perform Recovery Actions

Recovery actions are selected, scoped, prioritized, and performed

3 controls2 800-1714 800-1723 D3FEND2 mitigations

Completion evidence

What should exist when this playbook is working?

  • Approved incident-response plan with named roles and authorities.
  • Severity, declaration, escalation, containment, and recovery criteria.
  • Current internal and external contact and notification matrix.
  • Investigation logging, evidence preservation, and chain-of-custody procedures.
  • Technical containment and eradication runbooks.
  • Exercise and after-action records with completed improvements.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.