Framework Blending
Definition
The practice of combining elements of multiple IR frameworks: for example, using NIST as the strategic backbone, SANS phase names in operational playbooks, ISO/IEC 27035 for audit documentation, and CREST guidelines when procuring external IR services.
- Practice
- Combining multiple IR frameworks
- Example mix
- NIST backbone, SANS phase names, ISO/IEC 27035 for audit
- Also cited
- CREST guidelines for vendor procurement
- Domain
- Incident response programme design
Common questions
Why would an organisation blend frameworks rather than adopting a single standard end to end?+
Each framework has strengths for a different purpose: NIST's lifecycle is widely recognised for strategy, SANS phase terminology maps well to operational runbooks staff use daily, and ISO/IEC 27035 aligns with audit and certification requirements, so blending lets an organisation match the right tool to each need rather than forcing one framework to cover every use case.
What risk does framework blending introduce compared to using a single standard?+
Inconsistent terminology or process steps across the blended sources can create confusion during a live incident if staff trained on one framework's vocabulary encounter documentation using another's, so organisations that blend frameworks typically maintain a mapping document reconciling terms across the sources they use.
How does CREST fit into framework blending specifically for vendor-delivered incident response?+
CREST accreditation and guidelines are used to vet and select external IR service providers, giving assurance about a vendor's technical competence and process quality, which complements the organisation's internal framework choice rather than replacing it.
Related terms
- CREST
- A UK-based not-for-profit professional body that publishes practitioner-focused incident response guidelines and operates accreditation schemes for IR service providers. CREST guidance emphasises...
- ISO/IEC 27035
- An international standard for information security incident management. Part 1 covers principles and concepts; Part 2 covers planning and preparation. It defines...
- NIST SP 800-61
- The US National Institute of Standards and Technology's Computer Security Incident Handling Guide. It defines a four-phase IR lifecycle: Preparation; Detection and...
- Phase Granularity
- The number and specificity of discrete steps a framework defines within the IR lifecycle. Higher granularity, as in SANS PICERL's six steps...
- SANS PICERL
- A six-step incident response model developed through SANS Institute training: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. PICERL breaks NIST's combined response...