SANS PICERL · Incident Response · Evidence & Implementation Kit
Build a mature incident response capability on the SANS PICERL model, without writing the playbook yourself.
Every phase of the SANS incident response process handed to you as an adopt-ready control, from preparation and identification through containment, eradication, recovery and lessons learned, with the evidence of a mature IR capability.
IR-ready in a weekend, not after the breach.
Here is the honest situation. When an incident hits, the difference between a controlled response and chaos is the capability you built beforehand. The SANS Incident Handler's Handbook defines the six-phase PICERL process, preparation, identification, containment, eradication, recovery and lessons learned, that most mature teams run. Building that capability, the plan, the team, the jump bag, the forensic preservation and the lessons-learned loop, and evidencing it, is real work, and a response with no preparation or no post-incident review is exactly where incident response falls apart.
This Kit removes that build. It is every phase of the SANS PICERL process written as an adopt-ready control you personalize in a weekend, with the evidence of a mature IR capability.
What you get, the moment you buy
32
The six phases as adopt-ready controls. Every phase of the SANS PICERL process, from preparation and identification through containment, eradication, recovery and lessons learned, written so you personalize and run it. Forensic preservation is built in.
32
Evidence-of-maturity checklists. For each control, exactly the records that show a mature IR capability, plus where incident response falls apart, so you build capability not a document.
1
Incident Response Control Matrix, pre-built. Every control in a working spreadsheet, ready to record status and evidence location across the six phases.
1
Gap & Readiness Assessment. Score each control and the workbook returns your IR readiness as a single percentage, and exactly what to build next.
Grounded in the SANS Incident Handler's Handbook and the PICERL methodology, aligned with NIST SP 800-61, with preparation, forensic-preserving containment and the lessons-learned loop called out. Editable Word and Excel files.
Preparation is what wins the incident
Most of PICERL is what you do before an incident: the plan, the team, the jump bag, the access to logs and the drills. This Kit builds that preparation, so when an incident is declared your team responds from a ready capability rather than improvising under pressure.
What one control looks like
This is the incident response policy and plan, the foundation of preparation. All 32 are built to this depth.
IR-1 Incident response policy and authority PREPARATION
Implement this control
[Organization] shall maintain a board-approved incident response policy that defines incidents as any violation of policy, law, or unacceptable act involving information assets, states acceptable-use and monitoring expectations through login banners, assigns response authority to the incident response team, and is reviewed and reaffirmed at least annually.
Handler note.
SANS treats Preparation as the most crucial phase; the policy is the keystone. Aligns with NIST SP 800-61 Preparation.
Evidence of a mature IR capability
- Signed and dated incident response policy with version history
- System login banner text notifying users that activity is monitored
- Management approval record and annual review minutes
- Distribution or acknowledgement log confirming staff awareness of the policy
Common finding they raise: Many organizations run response on undocumented habit, leaving no legal footing when an employee is disciplined or evidence is challenged.
Why this is not another template pack
- The evidence is the point. An IR capability you cannot evidence is a document. This tells you the records that show maturity and where incident response falls apart, for every phase.
- Forensic preservation built in. Backing up and imaging systems before you touch them, and preserving chain of custody, are written into containment, so evidence survives the response.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. PICERL aligns with NIST SP 800-61 and feeds ISO 27035 incident management, so this work supports a broader security program.
Who buys this
Security and incident response teams building or maturing a capability, the IR and SOC leads who own it, and consultants standing up an IR program. Whether it is a first plan or a maturity uplift, you save weeks and walk in with the six phases and evidence structured.
By the end of the weekend you will have
✓ An adopt-ready control for all 32 items
✓ A completed incident response control matrix
✓ The evidence of a mature IR capability
✓ Your preparation and forensic preservation defined
✓ A readiness percentage and a build plan
✓ The common response failures designed out
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
What is PICERL? The six-phase SANS incident response process: Preparation, Identification, Containment, Eradication, Recovery and Lessons Learned. This Kit builds each phase as controls.
Does it align with NIST 800-61? Yes. PICERL maps onto the NIST SP 800-61 incident-handling lifecycle, and the Kit notes the alignment.
Does it cover forensics? Yes. Forensic imaging and chain of custody before containment changes are built in, so evidence survives the response.
What if it is not for me? A 30-day money-back guarantee.
Do not write the playbook during the breach.
Every PICERL phase is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be IR-ready this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com