Skip to main content
Back to all projects
Academic Project

Cybersecurity Incident-Response Workflow

Academic Project / Cybersecurity

A documented incident-response workflow covering identification through lessons learned and security-control improvement.

Academic Project / Cybersecurity

Workflow

  1. 01Identification
  2. 02Initial triage
  3. 03Evidence preservation
  4. 04Containment
  5. 05Eradication
  6. 06Recovery
  7. 07Documentation
  8. 08Lessons learned

Toolset

  • Incident response
  • Wireshark
  • Log review
  • NIST CSF
  • Documentation

Problem or objective

Response activity has to be ordered, evidence-preserving, and documented so that improvements can be made after the incident closes.

Rachel's role

Author of the workflow and supporting documentation.

Process

  1. 01Identification
  2. 02Initial triage
  3. 03Evidence preservation
  4. 04Containment
  5. 05Eradication
  6. 06Recovery
  7. 07Documentation
  8. 08Lessons learned
  9. 09Control improvements

Tools and technologies

  • Incident response
  • Wireshark
  • Log review
  • NIST CSF
  • Documentation

Security and ethical considerations

  • Evidence preserved before containment actions
  • Chain of documentation maintained through each phase
  • Findings routed into control improvements

Outcome

A clear, teachable response sequence suitable for tabletop use and documentation practice.

Academic project. It does not describe a real incident at any organization.