Concept and mechanism
An alert is a signal to assess rather than complete proof of incident scope. Correlate sources, identify assets, and decide containment according to evidence, urgency, and authority. With an active threat, waiting for definitive attribution can prolong impact. At the same time, indiscriminately erasing disks can destroy needed information. The runbook should permit proportionate actions and define escalation. Record who decided, what was observed, the action taken, and its service effect. Current NIST SP 800-61r3 integrates preparation and improvement into ongoing risk management alongside response activities.
Guided application
For timelines, preserve original logs and document time zones and clock offsets used in analysis. A summary does not replace evidence. Before closing recovery, address compromised credentials, validate integrity, and monitor recurrence signals; HTTP 200 alone does not prove eradication. When tuning alerts, scope exceptions to justified behavior and test what must remain detectable. For automation, prefer reversible actions when confidence is limited, with defined authority for destructive effects. A playbook needs rehearsal, scope limits, and success criteria to avoid turning false positives into outages.
If EDR and network evidence corroborate malicious activity, use authorized containment and retain feasible evidence. Then confirm the credential used in the attack cannot permit reentry.
Common pitfalls
Demanding absolute certainty before acting; modifying original logs; confusing a new VM with secure recovery; automating destruction with little evidence.
Related topics: Governance, risk, and suppliers · Controls, identity, and cryptography
Useful response reduces the threat while retaining reasoning and evidence for subsequent decisions.
Reference: Incident response and cybersecurity risk management · SY0-701 V7