The lifecycle
Read it left to right. Scope, contain, eradicate and recover repeat until scoping stops turning up new evidence. Decision makers sit behind the whole sequence rather than inside any one phase, because every gate needs them.
Why the loop is there
Figure 23 draws four activities as steps: isolate and gather evidence under contain, analyze and remove persistence under eradicate, each running once and in order.
Figure 24 draws the same four as they actually run. Isolation happens three times, evidence gathering starts and stops four times, and analysis runs underneath it all from early on. Plan for the second picture. Status reporting built on the first one contradicts itself by the third update.
Where the model came from
PICERL is the cycle most responders already know: preparation, identification, containment, eradication, recovery, lessons learned. All of it is here.
What PICERL leaves implicit is verification, triage and scope. They happen in every incident whether or not a model names them, and the unnamed activity is the one that gets skipped under pressure.
Scope, contain, eradicate and recover share the R because they repeat. Giving each its own letter would claim they run once each in order, which is the mistake this model exists to correct.
| Letter | Phase | What it covers | In PICERL |
|---|---|---|---|
| P | Preparation | Readiness, authority, tooling, exercises, hunting | Preparation |
| I | Identification | Alerting, detection and hunting, all running continuously | Identification |
| V | Verification | Establish that the event is an incident requiring a response | Named here. Left implicit. |
| T | Triage | Prioritize the incident against organizational objectives | Named here. Left implicit. |
| R | Response | Scope, contain, eradicate and recover, repeating until scoping produces nothing new | Containment, Eradication, Recovery, plus scope named here |
| D | Debrief | Close the incident and convert it into changes | Lessons Learned |
Verification and triage run together because both need the same conversation with decision makers. The hyphen marks where the incident ends and the closeout begins, and it stops the letters from being read as a word.
Start, work, finish, record
| Activity | Starts when | Core work | Done when | Record produced |
|---|---|---|---|---|
| P. Preparation | No incident running | Policy, authority, playbooks, backups, tooling, exercises, hunting | Never closes. Reopened by every debrief. | Authority matrix, playbooks, asset and contact lists |
| I. Identification | Telemetry and reports flowing | Operate detections, work alerts, hunt on a cadence | An event of interest is raised | Alert or hunt finding with evidence references |
| V, T. Verification and triage | Event of interest raised | Confirm it requires a response, rank it against organizational objectives | Continue, stop, or defer, with a name against it | Incident record, triage brief |
| R. Response (scope) | Verified incident, one or more indicators | Derive indicators, enterprise hunt, progressive sweep, attack timeline | Breadth, systems involved and potential impact established | Scope findings, attack timeline |
| R. Response (contain) | Reach of the compromise clear enough to act | Stop attacker activity, preserve evidence by volatility | Three validation channels show activity stopped | Containment decision record |
| R. Response (eradicate) | Evidence collected and preserved | Short-form investigation, remove persistence, rotate credentials, patch | Rerunning the original enumeration comes back clean | Root cause, eradication log |
| R. Response (recover) | Eradication verified | Verification checks, validation testing, owner sign-off, restoration | Systems in production under enhanced monitoring | Pre-restoration sign-off, owner acceptance |
| D. Debrief | Loop exited and signed | Close temporary assets, consolidate records, metrics, after-action review | Improvement plan issued with owners and dates | Incident report, metrics, improvement register |