SANS Incident Handler's Handbook and PICERL Methodology
Identification

SANS Incident Handler's Handbook and PICERL Methodology PICERL-I-01: Identification: Detection Sources and Alert Triage

Establish documented triage procedures for alerts from SIEM, EDR, NDR, threat intel, user reports, and third party notifications, with consistent severity scoring.

Other controls in Identification

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.