Authoritative Readings and Resources#
These resources extend the supplied learning chapters in AINS6301 Automated Response Systems. They were selected because they are primary standards, official documentation, open textbooks, or authoritative institutional guidance—not unsourced link lists.
How to Read Them#
For each module, read the supplied chapter first. Then use the two linked resources at the end of that chapter to test terminology, compare the course’s worked example with an authoritative treatment, and identify one point that should change or qualify your recommendation. Students are not expected to read every linked document cover to cover.
1. NIST Computer Security Incident Handling Guide#
Incident preparation, detection, containment, and recovery.
Use with: Incident response lifecycle, Containment and remediation automation, Human approval and escalation, Automated response readiness review.
2. CISA Incident Response Playbooks#
Operational playbook structure and escalation.
Use with: Incident response lifecycle, Playbooks and decision trees, Human approval and escalation, Testing response automation.
3. MITRE ATT&CK#
Technique-informed response and validation.
Use with: Playbooks and decision trees, SOAR and tool orchestration, Testing response automation, Post-incident learning.
4. NIST Cybersecurity Framework 2.0#
Respond and recover outcomes in organizational context.
Use with: SOAR and tool orchestration, Containment and remediation automation, Post-incident learning, Automated response readiness review.
Source-Use Standard#
Assignments should distinguish among measured notebook evidence, course-provided synthetic evidence, claims supported by these sources, and the student’s own professional judgment. Cite the specific page, section, control, or documentation topic used; a bare homepage link is not adequate evidence.