Incident Response
Security Incident Response Readiness Checklist
A NIST-aligned IR checklist for preparation, detection, containment, eradication, recovery, and lessons learned.
- Estimated time
- 4–10 Weeks
- Audience
- SOC, CISO, and Legal Teams
- Last updated
Operational reference for incident-response capability. Notification clocks under GDPR, NIS2, or sector rules still require legal assessment.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Prepare
Phase 2: Detect & Analyze
Phase 3: Contain, Eradicate, Recover
Phase 4: Post-Incident
FAQ
Which NIST publication covers IR?+–
NIST SP 800-61 is the common IR lifecycle reference.
Is a tabletop enough?+–
It is necessary but not sufficient. Technical failover and phishing-response drills add coverage.
Do we notify in 72 hours always?+–
GDPR has a 72-hour supervisory clock when a personal-data breach is likely to risk rights. Other laws differ.
Should we pay ransomware?+–
That is a legal, insurance, and sanctions decision—not a checklist item to pre-authorize here.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer