incident-response
Installation
SKILL.md
Incident Response Skill
Purpose
Defines security incident response procedures following NIST SP 800-61 and ISO 27001 Annex A.16.
Incident Classification
| Severity | Description | Response Time |
|---|---|---|
| Critical | Data breach, system compromise | Immediate (< 1 hour) |
| High | Active exploitation, service outage | < 4 hours |
| Medium | Vulnerability detected, policy violation | < 24 hours |
| Low | Minor security event, informational | < 72 hours |
Response Phases (NIST)
- Preparation — Tools, procedures, team readiness
- Detection & Analysis — Identify, classify, document
- Containment — Short-term and long-term containment
- Eradication — Remove threat, patch vulnerabilities
- Recovery — Restore systems, verify functionality
Related skills
More from hack23/riksdagsmonitor
osint-methodologies
OSINT collection, source evaluation, data integration, verification techniques for Swedish political intelligence
41economic-policy-analysis
Fiscal policy, budget analysis, economic forecasting, monetary policy, trade policy for political journalists
33electoral-analysis
Election forecasting models, campaign analysis, coalition prediction, voter behavior analysis for Swedish elections
25vulnerability-management
Vulnerability scanning, assessment, prioritization, and remediation processes following NIST and CIS Controls
25nist-csf-mapping
NIST Cybersecurity Framework 2.0 mapping for static HTML/CSS websites
24testing-strategy
Comprehensive testing strategy covering unit, integration, E2E, security, accessibility, and performance testing
23