Glossary

    Incident Response

    Incident Response

    Incident Response (IR) is the structured process for handling security incidents. The NIST SP 800-61 Rev. 2 framework defines four phases: (1) Preparation, (2) Detection & Analysis, (3) Containment, Eradication & Recovery, (4) Post-Incident Activity. In practice, these are commonly broken into operational steps:

    1. Detection: identify the incident through alerts, monitoring, or reports
    2. Containment: limit the blast radius (isolate instances, deactivate keys, block IPs)
    3. Eradication: remove the threat (delete backdoors, patch vulnerabilities, clean compromised resources)
    4. Recovery: restore normal operations (deploy clean resources, validate integrity, re-enable access)
    5. Lessons Learned: post-incident review, update runbooks, improve detection

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.