Skip to content

Framework Blending

Definition

The practice of combining elements of multiple IR frameworks: for example, using NIST as the strategic backbone, SANS phase names in operational playbooks, ISO/IEC 27035 for audit documentation, and CREST guidelines when procuring external IR services.

Practice
Combining multiple IR frameworks
Example mix
NIST backbone, SANS phase names, ISO/IEC 27035 for audit
Also cited
CREST guidelines for vendor procurement
Domain
Incident response programme design

Common questions

Why would an organisation blend frameworks rather than adopting a single standard end to end?+

Each framework has strengths for a different purpose: NIST's lifecycle is widely recognised for strategy, SANS phase terminology maps well to operational runbooks staff use daily, and ISO/IEC 27035 aligns with audit and certification requirements, so blending lets an organisation match the right tool to each need rather than forcing one framework to cover every use case.

What risk does framework blending introduce compared to using a single standard?+

Inconsistent terminology or process steps across the blended sources can create confusion during a live incident if staff trained on one framework's vocabulary encounter documentation using another's, so organisations that blend frameworks typically maintain a mapping document reconciling terms across the sources they use.

How does CREST fit into framework blending specifically for vendor-delivered incident response?+

CREST accreditation and guidelines are used to vet and select external IR service providers, giving assurance about a vendor's technical competence and process quality, which complements the organisation's internal framework choice rather than replacing it.

Related terms

CREST
A UK-based not-for-profit professional body that publishes practitioner-focused incident response guidelines and operates accreditation schemes for IR service providers. CREST guidance emphasises...
ISO/IEC 27035
An international standard for information security incident management. Part 1 covers principles and concepts; Part 2 covers planning and preparation. It defines...
NIST SP 800-61
The US National Institute of Standards and Technology's Computer Security Incident Handling Guide. It defines a four-phase IR lifecycle: Preparation; Detection and...
Phase Granularity
The number and specificity of discrete steps a framework defines within the IR lifecycle. Higher granularity, as in SANS PICERL's six steps...
SANS PICERL
A six-step incident response model developed through SANS Institute training: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. PICERL breaks NIST's combined response...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.