Incident Response

Concept

インシデントレスポンス(セキュリティ概念)

最終更新: 2026-07-28

4 References

https://www.refbase.ai/entity/incident-response

Knowledge Dossier

公開済みEvidenceをIdentity / Capability / Credibility / Use Case / Constraints・Current Statusの軸で機械的に集約したものです(新規の主張・推測は含みません)。

Identity

  • NIST公式Glossary(CSRC)は、incident handling(incident responseと同義に扱われる用語)を「The mitigation of violations of security policies and recommended practices(セキュリティポリシー・推奨実践への違反の低減)」と定義している(出典: CNSSI 4009-2015)。検証待ち incident response - Glossary | CSRC
  • NIST公式サイト(nvlpubs.nist.gov)によれば、NIST SP 800-61 Rev.3は「Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile」と題され、サイバーセキュリティリスクマネジメント全体にインシデント対応の推奨事項を組み込むことを目的とした公式文書である。検証待ち NIST SP 800-61r3

Capability

  • Rapid7公式ブログによれば、NIST SP 800-61が定めるインシデントレスポンスライフサイクルは「Preparation(準備)、Detection and analysis(検知と分析)、Containment, eradication and recovery(封じ込め・根絶・復旧)、Post-incident activity(事後対応)」の4フェーズから構成されるとされる。検証待ち Introduction to Incident Response Life Cycle of NIST SP 800-61 | Rapid7 Blog
  • Netscout公式サイトによれば、NIST SP 800-61モデルにおけるPhase 1(Preparation)は「preventing incidents and ensuring the capability to respond to them(インシデントの予防と対応能力の確保)」という2つの異なるカテゴリを含むとされ、Containment(封じ込め)はVLAN隔離等の技術的対応、Recovery(復旧)は脅威の根絶確認後に開始されるという段階的な構造を持つ。検証待ち NIST SP 800-61 | NETSCOUT

Credibility

公開Evidence未整備

Use Case

公開Evidence未整備

Constraints / Current Status

  • Incident Responseは検知・監視を担うMDR(マネージド検知対応)やEDR/XDR製品とは異なり、検知結果を受けて組織が実行する対応プロセス全体(準備・検知分析・封じ込め・根絶・復旧・事後対応)を指す概念であり、Mandiant等のインシデント対応専門企業(Google Cloud公式サイトが「incident response to business resilience」を提供するとする)が、この対応プロセスを外部専門家として支援するサービスの実装例である。検証待ち Mandiant Cybersecurity Consulting | Google Cloud

Key References

Knowledge Graph

References — 問い別の知識

データアクセス

各APIエンドポイントはJSON形式でデータを返します。生成AIのツール呼び出し・RAG連携での利用を想定しています。