Skip to content
ControlVerdict
IR.L2-3.6.1addresses
IR.L2-3.6.1Incident Handling
Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
  • [a]

    an operational incident-handling capability is established;
  • [b]

    the operational incident-handling capability includes preparation;
  • [c]

    the operational incident-handling capability includes detection;
  • [d]

    the operational incident-handling capability includes analysis;
  • [e]

    the operational incident-handling capability includes containment;
  • [f]

    the operational incident-handling capability includes recovery; and
  • [g]

    the operational incident-handling capability includes user response activities.

View full control

Six-phase runbook with a severity ladder on-call can follow at 2 a.m.

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. Only 2 verdicts so far.Last verdict Aug 2, 2026

Implementation

AO coverage. Addresses all Incident Handling objectives — an operational capability covering preparation, detection, analysis, containment, recovery, and user response activities.

Preparation. A named incident commander and two backups, an on-call rotation with a paging tool, a severity ladder pinned to the first page of the runbook, pre-authorized containment actions (isolate an endpoint, disable an account, block a sender) that on-call may take without waking an executive, an out-of-band communication channel that does not depend on the identity provider we might be evicting an attacker from, and printed contact cards for legal, the customer, and the provider. Preparation also includes the boring part: the asset inventory and network diagram the responder will need at 2 a.m.

Detection. Endpoint detections, identity risk events, and log-source alerts route to the paging tool with severity attached; the provider triages overnight and pages only on qualifying alerts. User reports arrive through a report-phish button and the help desk, and are treated as a detection source with the same intake path — several of our real incidents started there.

Analysis. Every page opens a case record. The responder establishes scope (which identities, which hosts, what data), determines whether CUI is implicated — a question asked explicitly on every case because it drives external reporting — and records a timeline as they go rather than reconstructing it afterward. The severity ladder is re-evaluated after initial analysis; downgrades are as normal as upgrades.

Containment. Pre-authorized actions first, then a containment decision by the incident commander weighing evidence preservation against spread. For identity compromise the standard play is revoke sessions, reset credentials, re-register authentication methods, and review what the account touched. Forensic images are taken before rebuild on any case where CUI exposure is plausible.

Recovery. Restore from known-good, validate the entry vector is closed before returning to service, and monitor the affected scope at elevated sensitivity for a defined watch period. Recovery is declared by the incident commander, not by whoever finished their task first.

User response activities. Users are told what to do (report, do not delete, do not investigate on your own), what will be asked of them, and what happens to their device. Affected users receive direct instructions during the incident; the workforce receives a short awareness note afterward when the lesson generalizes.

Maintenance. After-action review within ten business days on every qualifying incident, with action items tracked in the plan of action. Runbook revised whenever an after-action finds it wrong.

Accepted gap. We have no in-house forensic capability beyond memory and disk capture. Deep analysis is contracted to an incident response firm on retainer; the retainer, the engagement trigger, and the data-handling terms are documented so nobody negotiates a contract during an incident.

What the evidence looks like

  • Incident response plan with the phase runbooks and the severity ladder
  • On-call rotation export and a sample page-to-acknowledgment timeline
  • Redacted case record showing scope, CUI determination, timeline, and containment decision
  • Pre-authorized containment action list approved by management
  • After-action report with tracked action items, and the response firm retainer

Environment

OSC of ~300 staff with no in-house 24x7 SOC. After-hours coverage is a three-person on-call rotation backed by a managed detection and response retainer.

Tools

2 ratings on this revision

  • BarelyControlVerdict Assessor@cv-assessorAug 2, 2026

    Across the finish line

    Plan exists and names roles.

    Gaps

    Want evidence of at least one tabletop or real incident after-action that exercised the plan.

  • AlignedControlVerdict Implementer@cv-implementerOSCAug 2, 2026

    Across the finish line

    Incident handling roles and communication path are clear enough to tabletop.

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.