Incident Response: What an IS Auditor Checks
Report to CERT-In within 6 hours, keep logs 180 days in India, and know the lifecycle NIST rewrote in 2025.
Incident response is how an organisation detects, contains and recovers from a security incident: ransomware on a branch server, a leaked customer database, a compromised vendor account. The auditor's role is not to run it, but to judge whether the organisation is ready, whether it responded properly, and whether it met its reporting duties.
DISA Module 4 covers incident handling, cybersecurity frameworks and SIEM tools. Two things have moved since the course material was written in 2020: NIST rewrote its incident response guidance in April 2025, and Indian reporting rules now carry hard timelines.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Incident Response Lifecycle, Old and New
NIST SP 800-61 Rev. 2 (2012) set out four phases, the model most course material teaches. Rev. 3 (April 2025) replaces it with a model built on the six CSF 2.0 Functions and maps the old phases across.
Preparation
What happens
Policy, team, contacts, tools, playbooks, training
CSF 2.0 Functions in Rev. 3
Govern, Identify, Protect
Detection and Analysis
What happens
Spot the event, confirm it is an incident, judge scope and severity
CSF 2.0 Functions in Rev. 3
Detect, plus Identify (Improvement)
Containment, Eradication and Recovery
What happens
Limit the damage, remove the cause, restore systems
CSF 2.0 Functions in Rev. 3
Respond, Recover
Post-Incident Activity
What happens
Lessons learned, root cause, improvements
CSF 2.0 Functions in Rev. 3
Identify (Improvement)
| Rev. 2 phase | What happens | CSF 2.0 Functions in Rev. 3 |
|---|---|---|
| Preparation | Policy, team, contacts, tools, playbooks, training | Govern, Identify, Protect |
| Detection and Analysis | Spot the event, confirm it is an incident, judge scope and severity | Detect, plus Identify (Improvement) |
| Containment, Eradication and Recovery | Limit the damage, remove the cause, restore systems | Respond, Recover |
| Post-Incident Activity | Lessons learned, root cause, improvements | Identify (Improvement) |
Terms That Get Confused
- Event
- Any observable occurrence in a system, such as a login or a file change. Most events are harmless.
- Incident
- An event that actually or potentially harms confidentiality, integrity or availability, or breaks security policy.
- Containment
- Stopping the spread: isolating machines, disabling accounts. Comes before eradication.
- Eradication
- Removing the cause: malware, attacker accounts, the exploited weakness.
- SIEM
- Security information and event management: a system that collects logs from many sources, correlates them and raises alerts.
- Chain of custody
- A record of who handled evidence and when, so logs and images can be relied on later in an inquiry or court.
Indian Reporting and Logging Duties
| Rule | What it requires |
|---|---|
| CERT-In Directions, 28 April 2022 (under IT Act s.70B(6)) | Service providers, intermediaries, data centres, body corporates and government organisations must report the listed types of cyber incident to CERT-In within 6 hours of noticing them or being told of them |
| Same Directions | Logs of all ICT systems kept securely for a rolling 180 days within India; clocks synchronised to NIC or NPL time servers; a designated point of contact for CERT-In |
| IT Act s.70B(7) | Failing to provide information or comply with a CERT-In direction is punishable with imprisonment up to one year, a fine up to ₹1 lakh, or both |
| DPDP Act 2023 s.8(6) | On a personal data breach, the Data Fiduciary must inform the Data Protection Board and each affected Data Principal, without delay, then send the Board a detailed report within 72 hours of becoming aware (DPDP Rules 2025, rule 7). These duties commence in May 2027, eighteen months after the 13 November 2025 notification |
| RBI Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (31 July 2026) | Commercial banks must report cyber incidents to RBI within six hours of detection, on its DAKSH supervisory platform |
Quick practice on audit concepts. No signup.
What the Auditor Tests
- checkAn approved incident response policy and plan with named roles, escalation paths and severity levels
- checkEvidence the plan has been tested (tabletop exercises or drills) and updated afterwards
- checkAn incident register: sample incidents and trace detection, containment, closure and root cause
- checkTimestamps showing CERT-In and other regulatory reports went out within the required time
- checkSIEM coverage of critical systems, with alerts reviewed and acted on
- checkLog retention and clock synchronisation configured as the CERT-In Directions require
- checkLessons learned fed back into controls, not just recorded
How the DISA Assessment Test Tests This
Expect ordering questions (what should the team do first after confirming an incident?) and "auditor's primary concern" scenarios. The answer to "first step after confirming an incident" is containment, not eradication or restoration; the answer to "before an incident" questions is almost always preparation (plan, team, testing).
The trap is version drift. Questions built on the four-phase model are still fair, since Rev. 3 maps them rather than banning them, but don't be thrown if an option names CSF Functions instead. For Indian law, know three windows: 6 hours to CERT-In, 6 hours to RBI for commercial banks, and 72 hours for the detailed DPDP report to the Board (from May 2027). Options that swap them are the usual trap.
FAQs
What are the phases of incident response?expand_more
In NIST SP 800-61 Rev. 2: Preparation; Detection and Analysis; Containment, Eradication and Recovery; and Post-Incident Activity. Rev. 3 (April 2025) maps these to the six CSF 2.0 Functions.
Within how many hours must a cyber incident be reported to CERT-In?expand_more
Within 6 hours of noticing it or being told about it, under CERT-In's Directions of 28 April 2022 issued under section 70B(6) of the IT Act.
Does a bank report cyber incidents to RBI as well as CERT-In?expand_more
Yes. CERT-In's 6-hour rule applies to body corporates generally, and RBI's 2026 Directions separately require commercial banks to report cyber incidents to RBI within six hours of detection.
What is the difference between an event and an incident?expand_more
An event is any observable occurrence in a system. An incident is an event that harms or threatens confidentiality, integrity or availability, or violates security policy.
Next steps
- NIST CSF 2.0arrow_forward
- IS Operationsarrow_forward
- Audit Trail & Logsarrow_forward
- DPDP Actarrow_forward
Assessment Test format, timed and scored.
