NIST Aligned Process For Threat Management

This article highlights the Threat Management Process in Incident Response and brings in the understanding of the Kill chain model. Excerpts have been taken from a session presented at SACON - The Security Architecture Conference. You can view the full slide here.

For more in depth session on Incident Response, Threat Intel & many more - sign up for SACON here

8669802465?profile=original

3 Stages Of Incident LifeCycle

  • Detection & Analysis
  • Response & Recovery
  • Post incident

8669817271?profile=original

Read More: Bad USB Defense Strategies )

Threat Management - NIST Aligned Process

Detection & Analysis Detection & Analysis Detection & Analysis Response & Recovery Response & Recovery Response & Recovery Post Incident
Analyse Logs and Information Security Events Validate Incident Scale and Consequence Based on priority, assemble ISIRT and notify appropriate parties and escalate incidents. (e.g.. critical & high priority crisis and emergency incidents escalated to Country Emergency Manager) Direct ISIRT, develop incident response plan, activate rapid response team if needed and communicate incident to internal & external stakeholders Eradicate technical vulnerabilities and incident root causes Recover affected information systems and business operations Document lessons learnt
Identify potential information security incidents Assign consequence, severity and priority ratings Perform incident containment, investigation and root cause analysis, forensics and evidence management Close Incident
Categorize incident Review & confirm ratings Create incident review report
Endorse ratings Develop and implement IS-IM improvement recommendations

....view full table & slides here

( Read More: Incident Response: How To Respond To A Security Breach During First 24 Hours (Checklist) )

8669802070?profile=original

Votes: 0
E-mail me when people leave their comments –

Community Head, CISO Platform

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

CISO Platform Talks : Security FireSide Chat With A Top CISO or equivalent (bi-monthly)

  • Description:

    CISO Platform Talks: Security Fireside Chat With a Top CISO

    Join us for the CISOPlatform Fireside Chat, a power-packed 30-minute virtual conversation where we bring together some of the brightest minds in cybersecurity to share strategic insights, real-world experiences, and emerging trends. This exclusive monthly session is designed for senior cybersecurity leaders looking to stay ahead in an ever-evolving landscape.

    We’ve had the privilege of…

  • Created by: Biswajit Banerjee
  • Tags: ciso, fireside chat

CISO Meetup at BlackHat Las Vegas 2025

  • Description:

    We are excited to welcome you to the CISO Meetup during BlackHat USA 2025 in Las Vegas! Join us for an exclusive networking, meaningful conversations, and community building with top CISOs and cybersecurity leaders from around the globe. 

    Meetup Details:

    Location: Mandalay Bay, Las Vegas …

  • Created by: Biswajit Banerjee
  • Tags: ciso, black hat, black hat 2025, black hat usa

6 City Playbook Round Table Series (Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata)

  • Description:

    Join us for an exclusive 6-city roundtable series across Delhi, Mumbai, Bangalore, Pune, Chennai, and Kolkata. Curated for top cybersecurity leaders, this series will spotlight proven strategies, real-world insights, and impactful playbooks from the industry’s best.

    Network with peers, exchange ideas, and contribute to shaping the Top 100 Security Playbooks of the year.

    Date : Sept 2025 - Oct 2025

    Venue: Delhi, Mumbai, Bangalore, Pune,…

  • Created by: Biswajit Banerjee