Lists the procedures, contacts, and resources available to responders for various incident categories
CIRT responsible for developing profiles or scenarios of typical incidents (DDoS, virus/worm outbreak, data exfiltration by an external adversary, etc)
These profiles guide investigators in determining priorities and remediation plans
CIRT could also be responsible for making a Playbook