Skip to content

SANS PICERL

Definition

A six-step incident response model developed through SANS Institute training: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. PICERL breaks NIST's combined response phase into discrete named steps, giving teams more granular progress tracking during active incidents.

Developer
SANS Institute
Step count
6
Steps
Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned
Contrast
Splits NIST's combined response phase into discrete steps

Common questions

How does PICERL's containment/eradication/recovery split differ practically from NIST's model?+

NIST groups those activities into a single combined response phase, while PICERL separates them into three distinct named steps, which gives incident responders finer-grained checkpoints to track and report progress against during an active incident.

Why does the Lessons Learned step matter to a forensic investigator specifically?+

This step formalises a post-incident review that documents root cause, timeline, and evidence handling decisions, producing a record that can support both internal process improvement and any subsequent legal or regulatory inquiry into the incident.

Is PICERL meant to replace frameworks like NIST's incident response lifecycle?+

No. Organisations often choose one as their primary reference model based on training background or regulatory expectation, since both frameworks cover the same underlying activities with different granularity rather than fundamentally different content.

Related terms

CREST
A UK-based not-for-profit professional body that publishes practitioner-focused incident response guidelines and operates accreditation schemes for IR service providers. CREST guidance emphasises...
Framework Blending
The practice of combining elements of multiple IR frameworks: for example, using NIST as the strategic backbone, SANS phase names in operational...
ISO/IEC 27035
An international standard for information security incident management. Part 1 covers principles and concepts; Part 2 covers planning and preparation. It defines...
NIST SP 800-61
The US National Institute of Standards and Technology's Computer Security Incident Handling Guide. It defines a four-phase IR lifecycle: Preparation; Detection and...
Phase Granularity
The number and specificity of discrete steps a framework defines within the IR lifecycle. Higher granularity, as in SANS PICERL's six steps...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.