Back to all projectsAcademic Project Academic Project / Cybersecurity
Cybersecurity Incident-Response Workflow
Academic Project / Cybersecurity
A documented incident-response workflow covering identification through lessons learned and security-control improvement.
Workflow
- 01Identification
- 02Initial triage
- 03Evidence preservation
- 04Containment
- 05Eradication
- 06Recovery
- 07Documentation
- 08Lessons learned
Toolset
- Incident response
- Wireshark
- Log review
- NIST CSF
- Documentation
Problem or objective
Response activity has to be ordered, evidence-preserving, and documented so that improvements can be made after the incident closes.
Rachel's role
Author of the workflow and supporting documentation.
Process
- 01Identification
- 02Initial triage
- 03Evidence preservation
- 04Containment
- 05Eradication
- 06Recovery
- 07Documentation
- 08Lessons learned
- 09Control improvements
Tools and technologies
- Incident response
- Wireshark
- Log review
- NIST CSF
- Documentation
Security and ethical considerations
- Evidence preserved before containment actions
- Chain of documentation maintained through each phase
- Findings routed into control improvements
Outcome
A clear, teachable response sequence suitable for tabletop use and documentation practice.
Academic project. It does not describe a real incident at any organization.