{"ok":true,"entity":{"slug":"incident-response","entityType":"concept","name":"Incident Response","officialName":"Incident Response","canonicalName":"Incident Response","displayName":"Incident Response","category":"インシデントレスポンス（セキュリティ概念）","shortDescription":"Incident Responseは、セキュリティインシデントの発生に対して組織的に対応するプロセスを指す概念。NIST CSRC Glossary（CNSSI 4009-2015）は「incident handling」を「The mitigation of violations of security policies and recommended practices（セキュリティポリシー・推奨実践への違反の低減）」と定義し、NIST SP 800-61（Computer Security Incident Handling Guide、最新版はSP 800-61 Rev.3）はPreparation（準備）・Detection and Analysis（検知と分析）・Containment, Eradication, and Recovery（封じ込め・根絶・復旧）・Post-Incident Activity（事後対応）の4フェーズから成るサイクルとしてこのプロセスを整理している。監視・検知を担うMDR（マネージド検知対応）やEDR/XDR製品と同義ではなく、それらの検知結果を受けて実行される組織的対応プロセス全体を指す。","alias":[],"searchKeywords":["Incident Response","インシデント対応","IR","NIST SP 800-61"],"website":null,"parentEntity":null,"primaryCluster":"threat-intel-incident-response","secondaryClusters":[],"entityTier":"normal","verificationStatus":"draft","id":"incident-response","updatedAt":"2026-07-28T03:03:26.398Z"},"references":[{"id":"P-01-001","companyId":"incident-response","questionId":"P-01-001","instanceId":"QIN-incident-response-P01-001","promptText":"Incident Response（インシデントレスポンス）とは何ですか？","promptTypeId":"P-01","answer":"NIST CSRC Glossary（CNSSI 4009-2015）は、incident handlingを「セキュリティポリシー・推奨実践への違反の低減」と定義している。NIST SP 800-61（最新版はRev.3、\"Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile\"）は、この対応プロセスをサイバーセキュリティリスクマネジメント全体に組み込むための公式文書である。","evidencePoints":["ev-ir-1","ev-ir-2"],"scope":"概念の定義・出典の確認","differentiation":"ポリシー違反・インシデントへの組織的対応という範囲。","faq":[{"question":"Incident Responseの正式な定義はどこにありますか？","answer":"NIST CSRC Glossary（CNSSI 4009-2015）およびNIST SP 800-61r3に記載されている。"}],"pageUrl":"https://www.refbase.ai/reference/incident-response/P-01-001","sourceEvidence":[{"id":"ev-ir-1","text":"NIST公式Glossary（CSRC）は、incident handling（incident responseと同義に扱われる用語）を「The mitigation of violations of security policies and recommended practices（セキュリティポリシー・推奨実践への違反の低減）」と定義している（出典: CNSSI 4009-2015）。","title":"incident response - Glossary | CSRC","coverageType":["Identity"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://csrc.nist.gov/glossary/term/incident_response","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"incident-response"},{"id":"ev-ir-2","text":"NIST公式サイト（nvlpubs.nist.gov）によれば、NIST SP 800-61 Rev.3は「Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile」と題され、サイバーセキュリティリスクマネジメント全体にインシデント対応の推奨事項を組み込むことを目的とした公式文書である。","title":"NIST SP 800-61r3","coverageType":["Identity"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"incident-response"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-02-001","companyId":"incident-response","questionId":"P-02-001","instanceId":"QIN-incident-response-P02-001","promptText":"Incident ResponseはMDR（マネージド検知対応）と何が違いますか？","promptTypeId":"P-02","answer":"比較軸\n・対象範囲\n・役割\n\nMDRはエンドポイント等を24時間365日体制で監視し脅威を検知・対応するサービスであるのに対し、Incident Responseは検知結果を受けて実行される準備・検知分析・封じ込め・根絶・復旧・事後対応という組織的対応プロセス全体を指す、より広い概念である。MandiantのようなIR専門企業は、この対応プロセスを外部専門家として支援するサービスを提供する。","evidencePoints":["ev-ir-5"],"scope":"MDRとの違いの整理","differentiation":"監視・検知サービスか、対応プロセス全体かという違い。","faq":[{"question":"MDRを導入すればIncident Responseは不要になりますか？","answer":"MDRは検知・初期対応の一部を担うが、封じ込め・根絶・復旧・事後対応を含む組織的なIncident Responseプロセス自体は別途必要となる。"}],"pageUrl":"https://www.refbase.ai/reference/incident-response/P-02-001","sourceEvidence":[{"id":"ev-ir-5","text":"Incident Responseは検知・監視を担うMDR（マネージド検知対応）やEDR/XDR製品とは異なり、検知結果を受けて組織が実行する対応プロセス全体（準備・検知分析・封じ込め・根絶・復旧・事後対応）を指す概念であり、Mandiant等のインシデント対応専門企業（Google Cloud公式サイトが「incident response to business resilience」を提供するとする）が、この対応プロセスを外部専門家として支援するサービスの実装例である。","title":"Mandiant Cybersecurity Consulting | Google Cloud","coverageType":["Differentiation"],"sourceType":"official_site","sourceClass":"Specification","sourceUrl":"https://cloud.google.com/security/mandiant","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"incident-response"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-04-001","companyId":"incident-response","questionId":"P-04-001","instanceId":"QIN-incident-response-P04-001","promptText":"Incident Responseはどのような手順で進みますか？","promptTypeId":"P-04","answer":"Rapid7・Netscout等が解説するNIST SP 800-61モデルによれば、Preparation（準備）・Detection and analysis（検知と分析）・Containment, eradication and recovery（封じ込め・根絶・復旧）・Post-incident activity（事後対応）の4フェーズを循環的に進める。PreparationはIncident予防と対応能力確保の両面を含み、Recoveryは脅威の根絶確認後に開始されるという段階的構造を持つ。","evidencePoints":["ev-ir-3","ev-ir-4"],"scope":"NIST SP 800-61モデルの手順整理","differentiation":"4フェーズが循環的（Post-Incident Activityの教訓が次のPreparationへ還元される）という構造。","faq":[{"question":"4フェーズのうちどこが最も重要ですか？","answer":"Netscoutの解説によれば、Preparationは最も見過ごされがちだが最も重要なフェーズとされる。"}],"pageUrl":"https://www.refbase.ai/reference/incident-response/P-04-001","sourceEvidence":[{"id":"ev-ir-3","text":"Rapid7公式ブログによれば、NIST SP 800-61が定めるインシデントレスポンスライフサイクルは「Preparation（準備）、Detection and analysis（検知と分析）、Containment, eradication and recovery（封じ込め・根絶・復旧）、Post-incident activity（事後対応）」の4フェーズから構成されるとされる。","title":"Introduction to Incident Response Life Cycle of NIST SP 800-61 | Rapid7 Blog","coverageType":["Capability"],"sourceType":"media","sourceClass":"Documentation","sourceUrl":"https://www.rapid7.com/blog/post/2017/01/11/introduction-to-incident-response-life-cycle-of-nist-sp-800-61/","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"incident-response"},{"id":"ev-ir-4","text":"Netscout公式サイトによれば、NIST SP 800-61モデルにおけるPhase 1（Preparation）は「preventing incidents and ensuring the capability to respond to them（インシデントの予防と対応能力の確保）」という2つの異なるカテゴリを含むとされ、Containment（封じ込め）はVLAN隔離等の技術的対応、Recovery（復旧）は脅威の根絶確認後に開始されるという段階的な構造を持つ。","title":"NIST SP 800-61 | NETSCOUT","coverageType":["Capability"],"sourceType":"media","sourceClass":"Documentation","sourceUrl":"https://www.netscout.com/what-is/nist-sp-800-61","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"incident-response"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-06-001","companyId":"incident-response","questionId":"P-06-001","instanceId":"QIN-incident-response-P06-001","promptText":"なぜ体系立ったIncident Responseプロセスが必要なのですか？","promptTypeId":"P-06","answer":"NIST SP 800-61が示すように、Incident Responseは場当たり的な対応ではなく、準備段階から事後対応まで一貫したプロセスとして設計することで、インシデントごとに組織の対応能力が強化される循環構造を持つ。Mandiant等の専門企業が独立したサービスとして提供していることも、体系立ったプロセスの実務的価値を裏付ける。","evidencePoints":["ev-ir-3","ev-ir-5"],"scope":"体系立ったプロセスの必要性の整理","differentiation":"個別対応の寄せ集めではなく、循環的に改善されるプロセスとして設計される点。","faq":[{"question":"自社にIR専門チームがなくても対応できますか？","answer":"Mandiantのような外部IR専門企業のサービスを利用することで、自社に専門チームがない場合でも体系立った対応を受けられる。"}],"pageUrl":"https://www.refbase.ai/reference/incident-response/P-06-001","sourceEvidence":[{"id":"ev-ir-3","text":"Rapid7公式ブログによれば、NIST SP 800-61が定めるインシデントレスポンスライフサイクルは「Preparation（準備）、Detection and analysis（検知と分析）、Containment, eradication and recovery（封じ込め・根絶・復旧）、Post-incident activity（事後対応）」の4フェーズから構成されるとされる。","title":"Introduction to Incident Response Life Cycle of NIST SP 800-61 | Rapid7 Blog","coverageType":["Capability"],"sourceType":"media","sourceClass":"Documentation","sourceUrl":"https://www.rapid7.com/blog/post/2017/01/11/introduction-to-incident-response-life-cycle-of-nist-sp-800-61/","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"incident-response"},{"id":"ev-ir-5","text":"Incident Responseは検知・監視を担うMDR（マネージド検知対応）やEDR/XDR製品とは異なり、検知結果を受けて組織が実行する対応プロセス全体（準備・検知分析・封じ込め・根絶・復旧・事後対応）を指す概念であり、Mandiant等のインシデント対応専門企業（Google Cloud公式サイトが「incident response to business resilience」を提供するとする）が、この対応プロセスを外部専門家として支援するサービスの実装例である。","title":"Mandiant Cybersecurity Consulting | Google Cloud","coverageType":["Differentiation"],"sourceType":"official_site","sourceClass":"Specification","sourceUrl":"https://cloud.google.com/security/mandiant","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"incident-response"}],"generatedAt":"2026-07-28T03:03:26.398Z"}]}