Severity ladder

SEVTriggerEscalationNotification
SEV-1Active breach, exfil, ransomware, CIIImmediate, war-roomNCA <= 1h; SAMA <= 2h; PDPL 72h
SEV-2Critical exposure, privileged compromiseImmediateMitigation start <= 24h
SEV-3High CVE, suspicious auth, phishingPushRegister row <= 7d
SEV-4Compliance drift, expired certPush<= 30d
SEV-5InformationalNote-

Incident command lifecycle (NIST SP 800-61r2)

  1. Prepare - playbooks, contacts, access ready.
  2. Detection & analysis - validate, scope, classify.
  3. Containment - isolate; preserve evidence before wiping anything.
  4. Eradication - remove the cause; patch the vector.
  5. Recovery - restore, verify clean, monitor closely.
  6. Post-incident - lessons learned, control fixes, close.

Roles

Evidence & chain of custody

Hash (SHA-256) every artifact; store under the incident slug; never alter originals.

Follow the legal hold if litigation is anticipated.

+ legal authorisation.

← Administrator Guide  ·  All guidelines