FIRST CSIRT Services Framework v2.1 Service Area 1 - Information Security Event Management (ISEM). SCOPE: identification + analysis of security-relevant events (potential threats not yet escalated to incidents). SUB-SERVICES: (1) MONITORING + DETECTION - SIEM + IDS/IPS + EDR + NetFlow + threat-intel feeds + log aggregation + behavioural anomaly detection + UEBA + threat hunting at perimeter + endpoint + network + cloud + identity layers; (2) EVENT ANALYSIS - first-line triage + enrichment with contextual data + threat intel + asset criticality + likelihood + impact; (3) EVENT CATEGORIZATION + PRIORITIZATION - mapping events to risk levels + escalation criteria + handoff to ISIM if escalated to incident; (4) EVENT REPORTING - structured reporting per TLP + IEP + organisational channels.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.