Module 3: SOAR and tool orchestration#
AINS6301 — Automated Response Systems
Essential Question#
How do response systems coordinate tools?
Scenario#
an incident response team deciding which containment actions can be automated safely
Stakeholders: incident commander, security engineer, legal/compliance reviewer, and affected service owner
Core Moves#
Define the decision boundary
Compare baseline and alternative
Interpret evidence and assumptions
Identify failure modes
Recommend next action
Lab & Assignment#
Prototype a tool orchestration plan.
Artifact: automated response playbook with approval gates, rollback plan, and post-incident learning loop focused on soar and tool orchestration: Prototype a tool orchestration plan.