Files
Anthropic-Cybersecurity-Skills/skills/building-soc-escalation-matrix/references/standards.md
T

1.1 KiB

Standards - SOC Escalation Matrix

NIST SP 800-61 Rev 2 Incident Handling

  • Defines incident categories and severity levels
  • Recommends functional impact, information impact, and recoverability as factors
  • Guides escalation based on incident classification

ITIL Incident Management

  • P1-P4 priority classification framework
  • Impact x Urgency = Priority matrix
  • SLA management for each priority level

SOC-CMM (SOC Capability Maturity Model)

  • Level 1: Ad-hoc escalation, no formal process
  • Level 2: Defined escalation paths, documented SLAs
  • Level 3: Automated escalation with SOAR integration
  • Level 4: Context-driven escalation with risk scoring
  • Level 5: AI-assisted prioritization and auto-escalation

Response Time Standards

Priority Industry Standard Best Practice
P1 15 min response, 4h resolution 5 min response, 2h containment
P2 30 min response, 8h resolution 15 min response, 4h containment
P3 4h response, 24h resolution 2h response, 12h resolution
P4 8h response, 72h resolution 4h response, 48h resolution