main
GreySec Cyber Security Incident Response Plan (CSIRP)
Standardized incident response procedures following NIST SP 800-61.
Structure
containment/- Initial containment procedures and isolation stepseradication/- Threat removal and vulnerability remediationrecovery/- System restoration and monitoring procedurespost-incident/- Lessons learned and process improvementtemplates/- IR forms, checklists, and report templates
Severity Levels
| Level | Description | Response Time |
|---|---|---|
| Critical | Active breach, data exfiltration | Immediate |
| High | Confirmed malware, unauthorized access | 1 hour |
| Medium | Suspected intrusion, investigation needed | 4 hours |
| Low | Policy violation, minor anomaly | 24 hours |
Usage
See individual playbook directories for phase-specific procedures.
Description
Languages
Markdown
100%