Glossary

    Incident Response Playbook

    Incident Response

    An Incident Response Playbook is a documented, step-by-step procedure for handling a specific type of security incident. Playbooks reduce response time by eliminating decision paralysis during high-stress situations.

    Playbook Structure

    • Detection: how to identify this incident type (GuardDuty findings, alerts, user reports)
    • Severity Assessment: criteria for determining impact and urgency
    • Containment: immediate actions to stop the threat from spreading
    • Eradication: remove the threat completely (compromised resources, malware, backdoors)
    • Recovery: restore normal operations and verify systems are clean
    • Lessons Learned: post-incident review to improve defenses and update the playbook

    AWS-Specific Playbooks

    • Compromised IAM credentials (disable keys, revoke sessions, review CloudTrail)
    • Public S3 bucket (block public access, assess exposure, notify stakeholders)
    • Compromised EC2 instance (isolate, snapshot, forensic analysis)
    • Crypto mining detection (identify source, terminate instances, check billing)

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.