The **NIST incident response lifecycle** is another [[National Institute of Standards and Technology|NIST]] framework with additional sub-steps *dedicated to incident response*. This is a framework for incident response consisting of four phases:
- Preparation
- [[Detection and Analysis]]
- Containment, Eradication, and Recovery
- Post-incident activity
One thing to note is that the incident lifecycle isn't a linear process. It's a cycle, which means that steps can overlap as new discoveries are made.
All security [[Incident|incidents]] are [[Event|events]], but not all events are security incidents.
Understanding the composition of incident response teams will help you navigate an organisation’s hierarchy, openly collaborate and communicate with others, and work cohesively to respond to incidents.
- [[Computer Security Incident Response Teams|CSIRT]]