SOC & incident response · Lesson 3 of 5
Respond with a plan, not a panic
Incident response belongs inside broader cybersecurity risk management. NIST CSF 2.0 organizes outcomes under Govern, Identify, Protect, Detect, Respond, and Recover.
Coordinate action with evidence
Illustrative response decisions, not a replacement for an organization’s playbook.
- Assess & preserve
Identify affected entities and retain relevant records.
- Coordinate containment
Use the response plan and the required authority.
- Recover & learn
Verify recovery and improve safeguards and response procedures.
Read the visualWhy can unplanned deletion make a response harder?
It can destroy evidence and interrupt essential work. Coordinate actions under the response plan.
Prepare before an incident
Clarify roles, communication paths, important systems, and available evidence.
Respond deliberately
Assess the situation and coordinate actions that reduce harm while considering evidence and operational impact.
Recover and improve
Restore affected operations safely, then use what you learned to strengthen future preparation.
Put it in context
In a fictional exercise, a suspicious account accesses a sensitive system. The team follows its playbook, preserves relevant records, assesses scope, and coordinates containment with the system owner. Unplanned deletion could destroy evidence or interrupt essential work.
Use an approved response process, communicate clearly, and learn from the outcome.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.