Build the preparedness capability per NIST SP 800-61 Rev 2 Section 3.1 (Preparation). Preparation must address (a) Communications and Facilities: contact information (24/7 numbers + email + pagers + secure messaging) + on-call lists + escalation rosters + war room + secure storage for evidence + encryption for incident reports + jump bags + secure communication channels (encrypted email + signed messages + out-of-band channels for compromised-network scenarios), (b) Incident Analysis Hardware and Software: digital forensic workstations + laptops + spare equipment + blank removable media + portable printers + protocol analyzers + packet sniffers + forensic software + scripts and CDs/USB sticks + chain-of-custody supplies, (c) Incident Analysis Resources: port lists + documentation for operating systems + applications + protocols + intrusion detection signatures + network diagrams + lists of critical assets + baselines of expected network and system activity + hash sums of critical files, (d) Incident Mitigation Software: clean operating system and application media + backup images, (e) Training and Exercises: tabletop + technical exercises + new staff onboarding + cross-training, (f) Threat Intelligence consumption (CISA + sector ISAC + commercial feeds) to anticipate incidents.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.