FIRST CSIRT Services Framework and Standards
FIRST: Service Area 2 - Information Security Incident Management

FIRST CSIRT Services Framework and Standards FIRST-CSIRTF-SA2-ISIM: Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

FIRST CSIRT Services Framework v2.1 Service Area 2 - Information Security Incident Management (ISIM). SCOPE: end-to-end management of confirmed incidents from intake through closure + lessons learned. SUB-SERVICES: (1) INCIDENT REPORT ACCEPTANCE - intake from constituency + sensors + external sources; identity verification + handling per TLP; ticket creation; SLA tracking; (2) INCIDENT ANALYSIS - root-cause investigation + indicators-of-compromise enumeration + scope determination + timeline reconstruction + threat-actor attribution support; (3) ARTEFACT + FORENSIC EVIDENCE ANALYSIS - malware + memory + disk + network forensics + chain-of-custody + tool selection; (4) MITIGATION + RECOVERY - containment + eradication + recovery + post-incident hardening; (5) INCIDENT COORDINATION - cross-organisational + national + international coordination including peer CSIRTs + law enforcement + ISACs + vendors + customers + media; (6) CRISIS MANAGEMENT SUPPORT - escalation to executive + crisis-team + business-continuity + communications + legal + insurance + regulatory notification; (7) INCIDENT RESPONSE SUPPORT to constituency including playbook delivery + on-site assistance + remote assistance.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.