{"ok":true,"entity":{"id":"incident-response","name":"Incident Response","entityType":"concept","officialName":"Incident Response","canonicalName":"Incident Response","displayName":"Incident Response","category":"インシデントレスポンス（セキュリティ概念）","shortDescription":"Incident Responseは、セキュリティインシデントの発生に対して組織的に対応するプロセスを指す概念。NIST CSRC Glossary（CNSSI 4009-2015）は「incident handling」を「The mitigation of violations of security policies and recommended practices（セキュリティポリシー・推奨実践への違反の低減）」と定義し、NIST SP 800-61（Computer Security Incident Handling Guide、最新版はSP 800-61 Rev.3）はPreparation（準備）・Detection and Analysis（検知と分析）・Containment, Eradication, and Recovery（封じ込め・根絶・復旧）・Post-Incident Activity（事後対応）の4フェーズから成るサイクルとしてこのプロセスを整理している。監視・検知を担うMDR（マネージド検知対応）やEDR/XDR製品と同義ではなく、それらの検知結果を受けて実行される組織的対応プロセス全体を指す。","primaryCluster":"threat-intel-incident-response","parentEntity":null,"verificationStatus":"draft","website":null,"updatedAt":"2026-07-28T03:03:26.398Z","secondaryClusters":[],"alias":[],"searchKeywords":["Incident Response","インシデント対応","IR","NIST SP 800-61"]},"referenceIndex":["P-01-001","P-02-001","P-04-001","P-06-001","P-02-002"]}