FIRST: Service Area 2 - Information Security Incident Management
FIRST CSIRT Services Framework and Standards FIRST-CSIRTF-SA2-ISIM: Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)
FIRST CSIRT Services Framework v2.1 Service Area 2 - Information Security Incident Management (ISIM). SCOPE: end-to-end management of confirmed incidents from intake through closure + lessons learned. SUB-SERVICES: (1) INCIDENT REPORT ACCEPTANCE - intake from constituency + sensors + external sources; identity verification + handling per TLP; ticket creation; SLA tracking; (2) INCIDENT ANALYSIS - root-cause investigation + indicators-of-compromise enumeration + scope determination + timeline reconstruction + threat-actor attribution support; (3) ARTEFACT + FORENSIC EVIDENCE ANALYSIS - malware + memory + disk + network forensics + chain-of-custody + tool selection; (4) MITIGATION + RECOVERY - containment + eradication + recovery + post-incident hardening; (5) INCIDENT COORDINATION - cross-organisational + national + international coordination including peer CSIRTs + law enforcement + ISACs + vendors + customers + media; (6) CRISIS MANAGEMENT SUPPORT - escalation to executive + crisis-team + business-continuity + communications + legal + insurance + regulatory notification; (7) INCIDENT RESPONSE SUPPORT to constituency including playbook delivery + on-site assistance + remote assistance.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 98 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.