Incident Response

(5)

Incident response covers the processes, playbooks, and tooling organizations use to detect, contain, and recover from security incidents. Coverage of IR planning, NIST and SANS frameworks, SIEM and SOAR integration, tabletop exercises, forensic preservation, regulatory notification requirements, and the post-incident reviews that drive control improvements.