FIELD FRAMEWORK / VERSION 2.1

Incident Detection & Response Framework

Operational guidance for the people making technical and business decisions during an incident.

Built for security operations, engineering, infrastructure, identity, cloud, legal, privacy, and business owners. Adapt the decision authority, telemetry, tooling, and regulatory paths to your environment before an incident.

Last reviewed: September 1, 2026Maintainer: Leandro RochaTime basis: UTC during incidents
OPERATING MODEL

Use the framework as a decision system

The objective is not to follow a document mechanically. It is to establish reliable evidence, explicit authority, reversible containment where possible, and measurable recovery criteria.

Known factsTelemetry, observations, and verified business impact.
AssumptionsWorking hypotheses with an owner and confidence level.
DecisionAction, authority, tradeoff, and expected result.
ValidationEvidence that the action worked and did not create unacceptable impact.
WORKFLOW

Operational response loop

This six-stage workflow supports active response. It complements NIST SP 800-61 Rev. 3 and NIST CSF 2.0; it is not intended to replace organization-wide cybersecurity risk management.

1. PrepareAuthority, telemetry, access, communications, and recovery capability.
2. ValidateConfirm malicious activity and establish confidence.
3. ScopeIdentity, endpoint, network, cloud, SaaS, data, and business impact.
4. ContainChoose authorized actions and verify their effect.
5. RecoverRemove persistence, restore trust, and monitor stability.
6. ImproveTest corrective actions and feed lessons into preparation.
WORKING AREAS

Move from signal to controlled recovery

01 / DETECTION

Build evidence, not alert volume

Telemetry requirements, detections-as-code, triage, ATT&CK mapping, validation, and coverage metrics.

Open detection engineering β†’
02 / RESPONSE

Make accountable decisions

Roles, severity, evidence discipline, containment gates, communications, recovery criteria, and exercises.

Open response procedures β†’
03 / PLAYBOOKS

Execute with safeguards

Scenario-specific actions with decision authority, evidence requirements, rollback, and validation.

Open incident playbooks β†’
04 / FIELD KIT

Use responder-ready artifacts

Severity, evidence, cloud, identity, ransomware, executive-update, and post-incident templates.

Open the field kit β†’
05 / AI SECURITY IR

Control models, agents, data, and tools

AI/LLM lifecycle, evidence requirements, authority reduction, rollback, and the operational AI-IR-01 playbook.

Open AI Security IR β†’
06 / SOFTWARE SUPPLY CHAIN

Recover repositories from trusted evidence

Repository, maintainer, workflow, dependency, credential, package, release, and artifact compromise response.

Open repository response β†’
BOUNDARIES

What this framework isβ€”and is not

Designed to support

  • Preparation and tabletop exercises
  • Initial validation and incident coordination
  • Technical investigation and evidence preservation
  • Containment and recovery decisions
  • Post-incident corrective action

Requires local adaptation

  • Legal and regulatory obligations
  • Business impact and safety constraints
  • Tool commands, permissions, and retention
  • Insurance, communications, and law-enforcement paths
  • Approval thresholds and delegated authority

Before using this during a live incident

Confirm the incident lead, protected communication channel, evidence repository, time standard, emergency access path, escalation tree, recovery owners, and authority for disruptive containment.