Question

Difficulty: EasyIncident Response Process and Playbooks

An organization is updating its cybersecurity procedures to follow the standard NIST SP 800-61 incident response framework. In which sequential order should the cybersecurity team execute the four primary phases of the incident response lifecycle from beginning to end?

  1. 1Preparation
  2. 2Detection and Analysis
  3. 3Containment, Eradication, and Recovery
  4. 4Post-Incident Activity

Answer

The correct sequential order of the NIST incident response lifecycle phases is Preparation, followed by Detection and Analysis, followed by Containment, Eradication, and Recovery, and ending with Post-Incident Activity.
According to the NIST SP 800-61 guidelines, the standard incident response lifecycle proceeds sequentially through four main phases: Preparation (setting up plans and capabilities), Detection and Analysis (discovering and investigating the security event), Containment, Eradication, and Recovery (limiting impact, eliminating the threat, and restoring systems), and Post-Incident Activity (reviewing lessons learned to refine future response).

Step-by-Step Solution

1
Identify the proactive groundwork phase
Preparation is established as the necessary starting phase before any active incident occurs.
An organization must prepare infrastructure, policies, and response capabilities prior to detecting an attack.
2
Determine the initial reactive phase during an active event
Detection and Analysis follows Preparation.
Once an incident occurs, the team must detect indicators of compromise and analyze logs to confirm the event.
3
Identify the active remediation phase
Containment, Eradication, and Recovery comes third.
After confirming the incident, immediate containment limits damage, eradication removes threat elements, and recovery restores normal operations.
4
Identify the wrap-up and review phase
Post-Incident Activity is the final phase.
Lessons learned and post-mortem analysis can only be completed after systems are fully recovered and stabilized.

Key Concept

NIST SP 800-61 Incident Response Lifecycle Phases
Rate this question