2.1 Incident Response Preparation, Policies, and Playbook Design
Key Takeaways
Preparation remains foundational in EC-Council's process and legacy NIST SP 800-61 Rev. 2 terminology; current NIST SP 800-61 Rev. 3 distributes preparation across the Govern, Identify, and Protect Functions of CSF 2.0.
An Incident Response Policy uses executive sponsorship to define incident-response authority, including which containment and evidence-preservation actions are delegated and which require approval from a named risk owner.
Incident response playbooks provide scenario-specific decision trees that reduce ambiguity during critical events such as ransomware outbreaks, data exfiltration, and denial of service attacks.
A forensic jump bag must maintain pre-validated hardware write blockers, clean bootable forensic operating systems, sterile forensically wiped storage media, and printed offline documentation.
Contact lists and escalation call trees must incorporate verified primary and secondary out-of-band communication paths across internal stakeholders, external retainers, regulators, and law enforcement.
2.1 Incident Response Preparation, Policies, and Playbook Design
Incident handling success is determined long before an adversary breaches an enterprise perimeter. In EC-Council terminology and the legacy NIST SP 800-61 Rev. 2 lifecycle, the Preparation phase establishes the proactive foundation for incident response. Current NIST SP 800-61 Rev. 3 superseded Rev. 2 in April 2025 and distributes preparation across the Govern, Identify, and Protect Functions of CSF 2.0. While subsequent phases react to ongoing intrusions, Preparation establishes the governance authority, technical tooling, forensic infrastructure, and standardized workflows required to confront high-impact cyber threats.
Incident Response Policy: Authority and Core Governance
An Incident Response Policy is a mandatory governance document authorized and signed by executive leadership. Executive sponsorship documents the authority delegated to incident handlers for emergency containment—such as isolating systems or revoking credentials—within approved thresholds. Business-risk acceptance and actions outside that delegation still require the named decision owner.
A compliant Incident Response Policy incorporates six core components:
- Management Commitment and Purpose: Establishes organizational intent to safeguard data confidentiality, system integrity, and service availability, while minimizing financial loss and brand impairment.
- Scope and Applicability: Governs all enterprise environments, including on-premises networks, multi-cloud platforms (IaaS, PaaS, SaaS), operational technology (OT/SCADA), mobile endpoints, and third-party vendor connections.
- Definition of Events versus Incidents: Differentiates observable occurrences from policy violations:
- Computer Security Event: Any observable occurrence within a network, system, or application (e.g., a firewall dropping an unsolicited packet or a user logging into a file share).
- Computer Security Incident: A confirmed violation or imminent threat of violation of security policies resulting in data compromise, unauthorized access, or service disruption.
- Organizational Structure and Roles: Establishes the Computer Security Incident Response Team (CSIRT) hierarchy, detailing responsibilities across technical handlers, legal counsel, human resources, and communications using a RACI matrix.
- Prioritization Criteria and SLAs: Defines severity classifications and mandatory response Service Level Agreements (SLAs).
- Maintenance and Metrics: Defines a risk-based policy review cadence and tracks operational metrics, including Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR).
The Incident Response Plan (IRP) Structure
While policy establishes authority, the Incident Response Plan (IRP) acts as the operational roadmap detailing how the enterprise coordinates and executes defense. The IRP aligns directly with the organization's Business Continuity Plan (BCP) and Disaster Recovery (DR) framework to ensure organizational resilience.
The IRP defines standard procedures across six operational phases:
- Preparation: Hardening infrastructure, establishing forensic baselines, deploying detection telemetry, and conducting training.
- Detection and Analysis: Ingesting alerts, establishing chronological timelines, and formulating working hypotheses.
- Containment: Applying short-term isolation and long-term network segmentation to arrest threat progression.
- Eradication: Removing malicious artifacts, terminating adversary persistence, and patching vulnerabilities.
- Recovery: Restoring systems from validated, protected backups and validating services in production.
- Post-Incident Activity: Conducting lessons-learned debriefings, updating playbooks, and preserving evidence archives.
Scenario-Specific Playbook Design
Incident Response Playbooks are tactical decision trees that guide technical responders through specific threat vectors, reducing cognitive load while preserving decision gates for uncertain or high-impact actions:
- Ransomware Playbook: Focuses on immediate containment to prevent enterprise-wide encryption. Key decision nodes require isolating affected hosts from the network (disabling network interfaces or applying EDR host isolation), capturing volatile RAM memory before rebooting to preserve ephemeral cryptographic keys, verifying the integrity of offline immutable backups and Volume Shadow Copies, querying threat intelligence repositories for published decryptors, and rotating Kerberos
krbtgtcredentials through a tested two-reset procedure only when domain-ticket compromise evidence or the recovery plan warrants it. - Data Breach / Exfiltration Playbook: Targets active unauthorized data movement. Key procedures involve inspecting egress traffic channels (unusual outbound HTTPS, DNS tunneling, or cloud sync utilities), applying network shunts to sever adversary command-and-control (C2) links, capturing volatile network sockets via netstat, invalidating active OAuth and SAML tokens, and quantifying stolen record volumes using Data Loss Prevention (DLP) and NetFlow telemetry.
- Denial of Service (DoS/DDoS) Playbook: Addresses availability collapse. The workflow classifies the attack vector between Layer 3/4 volumetric floods (SYN, UDP, ICMP) and Layer 7 application resource exhaustion, reroutes ingress traffic through upstream ISP or cloud scrubbing centers, applies BGP Anycast and Remotely Triggered Black Hole (RTBH) filtering, and activates Web Application Firewall (WAF) rate limiting.
Forensic Jump Bags and Hardware IR Toolkits
A Forensic Jump Bag is a portable, pre-configured emergency kit containing hardware, specialized software, and physical supplies required to deploy on-site to an infected facility or analyze an isolated, air-gapped host.
Essential Jump Bag components include:
- Hardware Write Blockers: Physical bridge devices (such as Tableau or WiebeTech bridges supporting SATA, SAS, PCIe, NVMe, and USB interfaces) that intercept and suppress write commands at the hardware controller level, reducing the risk that supported write commands alter source media during bit-stream acquisition; responders validate the blocker and verify hashes rather than claim an absolute guarantee.
- Sterile External Storage: High-capacity external drives forensically wiped using zero-byte patterns and verified with cryptographic SHA-256 hashes to prevent cross-contamination.
- Clean Bootable Media: Trusted, read-only USB drives containing live forensic operating systems (CAINE, SANS SIFT, Paladin) allowing analysts to boot compromised endpoints without executing local malware.
- Forensic Imaging Software: Validated utilities (FTK Imager, dc3dd, Guymager) capable of generating bit-for-bit raw images or standardized forensic containers (E01, AFF4).
- Physical Evidentiary Supplies: Tamper-evident evidence bags, antistatic packaging, Faraday bags (blocking RF signals on mobile devices), barcode labels, security seals, and null-modem cables.
- Hardcopy Documentation: Laminated escalation call trees, physical contact directories, chain of custody forms, and printed playbooks. In widespread ransomware incidents where domain controllers, internal email, and intranet shares are encrypted, printed hardcopies remain a resilient reference when compromised or unavailable enterprise systems cannot be trusted.
Contact Lists, Call Trees, and Operational Readiness
Maintaining verified internal and external contact directories is critical for rapid mobilization:
- Internal Call Trees: Detail primary and secondary escalation pathways connecting the Incident Commander, lead forensic analysts, network engineering leads, General Counsel, CISO, and Public Relations.
- External Directories: Maintain 24/7 hotline numbers for retained Digital Forensics and Incident Response (DFIR) service providers, cyber insurance claims teams, specialized breach counsel, regulatory contacts, and federal law enforcement (FBI Cyber Task Forces, CISA).
- Operational Drills: Call trees and playbooks should be exercised at a risk-based, policy-defined cadence, with communications checks often performed more frequently, so contact numbers and out-of-band identities remain accurate despite personnel turnover.
What is the primary technical function of a hardware write blocker utilized during the physical acquisition phase of a digital forensic jump bag deployment?
It intercepts and prevents write commands from reaching the source evidence drive while allowing read operations for bitstream acquisition
It automatically formats destination storage media with a cryptographically verified zero-byte pattern
It injects an encrypted kernel into host memory to disable local administrative rootkits during drive extraction
It accelerates the read throughput of solid-state storage arrays by stripping file system metadata
Which of the following describes the key governance distinction between an Incident Response Policy and an Incident Response Playbook?
Policies contain specific command-line instructions for containment, whereas playbooks outline executive compensation and shareholder reporting
Policies establish high-level authority, scope, and organizational mandates chartered by executive management, whereas playbooks provide deterministic, scenario-specific technical procedures
Policies are drafted exclusively by third-party external retainers, whereas playbooks are statutory documents filed with regulatory agencies
Policies are only enacted during active system outages, whereas playbooks govern everyday IT helpdesk ticket resolution
During an enterprise-wide ransomware attack that encrypts primary domain controllers, virtualization clusters, and internal email systems, which preparation artifact is most essential for maintaining command and control of the response?
A cloud-hosted Jira Kanban board synchronized with local directory services
An automated webhook script running inside the primary hypervisor cluster
Laminated, hardcopy contact call trees and printed scenario playbooks stored in the forensic jump bag
A shared network file share containing historical PDF incident reports
Sections you finish are checked off in the contents.