Playbook
Definition
A documented step-by-step procedure for responding to a specific type of security event. Playbooks standardise analyst behaviour, reduce response time, and ensure critical steps such as containment and evidence preservation are not skipped.
- Type
- Documented incident response procedure
- Scope
- One specific event type, e.g. ransomware or phishing
- Purpose
- Standardise analyst behaviour, cut response time
- Includes
- Containment and evidence preservation steps
Common questions
How does a playbook differ from a general incident response plan?+
The overall response plan sets organisation-wide roles, escalation paths, and communication rules, while a playbook drills into the specific technical steps for one scenario, such as isolating a host and preserving memory during a ransomware event.
Why do playbooks matter for evidence preservation specifically?+
Under time pressure, an analyst without a playbook may reboot or wipe a compromised system to restore service quickly, destroying volatile memory and log data; a playbook forces preservation steps to happen before remediation steps that would erase evidence.
Who typically maintains and updates an organisation's playbooks?+
Security operations center leads or incident response managers own playbooks, updating them after tabletop exercises or real incidents reveal gaps, such as a step that assumed access to a system that turned out to be unavailable during a real event.
Related terms
- Decision Gate
- A checkpoint within a playbook at which the responder must evaluate a condition, such as whether data exfiltration has been confirmed, and...
- Escalation Path
- The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
- Indicators of Compromise (IoCs)
- Artefacts observed on a network or system that suggest an intrusion or malicious activity has occurred, such as unusual outbound connections, known-malicious...
- Managed Security Service Provider (MSSP)
- A third-party organisation that delivers security monitoring, tooling, and analyst coverage as a contracted service. Used in fully outsourced and co-managed SOC...
- Runbook
- A technical execution document, sometimes used interchangeably with playbook but more precisely refers to the low-level commands and scripts used during a...
- Security Operations Centre (SOC)
- The dedicated team and technology platform responsible for continuous monitoring, detection, analysis, and coordinated response to security events. May be in-house, co-managed,...
- SIEM (Security Information and Event Management)
- A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...
- SOAR
- Security Orchestration, Automation and Response. A platform that can execute playbook steps automatically, such as blocking an IP address or disabling a...
- Tabletop Exercise
- A structured, discussion-based simulation in which team members walk through a hypothetical incident using the playbook as a guide, without touching live...
- Threat Hunting
- A proactive, human-led process that searches for evidence of adversary activity in an environment under the assumption that automated controls have been...
Explained in these topics
- Developing and Using Incident Response PlaybooksA scenario-specific IR document that prescribes the exact steps, decision gates, tools, and responsible roles for handling one class of incident. Subordinate t...
- SOC Structure and the Tier Model