Skip to main content

07 - References and Further Reading

To deepen your understanding of Incident Response, refer to the following industry standards, frameworks, and tool documentation.

Standards and Frameworks

  • NIST SP 800-61 Revision 2: Computer Security Incident Handling Guide

  • SANS Incident Handler's Handbook

    • Description: A practical, widely-used guide outlining the 6 steps of incident response (PICERL: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned).
    • Link: https://www.sans.org/white-papers/33901/
  • MITRE ATT&CK Framework

    • Description: A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. Essential for understanding attacker behavior during the Analysis phase.
    • Link: https://attack.mitre.org/

Forensic Tools Documentation

Cloud Incident Response

Share this guide