Technical-Security-Documentation

Incident Response Runbook: Oil & Gas Operations

Phase 1: Detection and Identification

[cite_start]Determine if an event is a routine glitch or a malicious incident[cite: 76].

Phase 2: Activation and Mobilization

[cite_start]Activate the Cyber-Incident Response Team (CIRT)[cite: 85].

Phase 3: Containment (Isolation)

[cite_start]Priority: Safety over Data[cite: 93].

Phase 4: Eradication and Neutralization

Phase 5: Recovery and Restoration

Phase 6: Post-Incident Activity

[cite_start]CRITICAL WARNING: Never patch a live control system during an active incident without a verified safety plan; doing so may trigger process failures or explosions[cite: 121].