TEAM VIEW // RESPONSE SWIMLANE
Who moves, and in what order
Pick the threat. The response paints immediately, sequenced by NIST CSF 2.0 function, with a delegation fallback for lean teams.
THE ANSWER
Can your team run this response?
Your team covers this response. All 12 roles GTG-1002 needs are selected. First move is Detection Engineer, on a signal that fires from M-A4-01.
Roles required
12
Roles required for the live response
Steps
17
Steps in the live flow, Detect to Recover
First move
Detection Engineer
First move once the signal trips
Detection trigger
M-A4-01
Control IDs for this detection
Lean team: 4 roles cover 20 of 32 steps. 12 fall to the CISO as last resort.
01THREAT SCENARIO1 OF 21
GTG-1002
WHAT TRIPS THE LIVE FLOW
Thousands of agent requests per second from one identity
M-A4-01
If this detection is not deployed, nothing below Detect happens.
Direction AIN THE WILD
The autonomy threshold. Defines tier-5 AI capability for the framework.
02YOUR ROLES12 OF 19 SELECTED
Who do you actually have?
Hybrid cloud · SIEM · EDR / XDR · CI/CD
Evaluating new capability? See Stack Lab at /stack03THE RESPONSE17 STEPS
DetectLIVE FLOW6 steps
RespondLIVE FLOW6 steps
RecoverLIVE FLOW5 steps
16 handoffs across the live flow. No steps are covered by another role.
04THE FULL SWIMLANEALL FUNCTIONS
Overview: role coverage by CSF function
Counts show how many steps each role holds in each function for the selected class (A4). Click a column header, or a function above, to zoom into that function's numbered flow.
| Role | Govern | Identify | Protect | Detect | Respond | Recover | Total |
|---|---|---|---|---|---|---|---|
| CISO / Head of Security | 2 | no steps | no steps | no steps | 1 | no steps | 3 |
| CRO / Board Risk | 3 | no steps | no steps | no steps | no steps | 1 | 4 |
| SOC Manager | no steps | no steps | no steps | 1 | no steps | 1 | 2 |
| Tier 1 Analyst | no steps | no steps | no steps | 1 | no steps | no steps | 1 |
| Tier 2 Analyst | no steps | no steps | no steps | 1 | no steps | no steps | 1 |
| Threat Hunter | no steps | no steps | no steps | 1 | no steps | no steps | 1 |
| Incident Responder | no steps | no steps | no steps | no steps | 1 | 1 | 2 |
| Detection Engineer | no steps | no steps | no steps | 1 | no steps | 1 | 2 |
| Cloud Security Engineer | no steps | 1 | no steps | no steps | 1 | no steps | 2 |
| Network / Security Engineer | no steps | no steps | 1 | no steps | 1 | no steps | 2 |
| Data Owner / Privacy | 1 | 1 | no steps | no steps | 1 | 1 | 4 |
| IAM / Identity Owner | no steps | 1 | 2 | 1 | 1 | no steps | 5 |
05LEAN TEAM FALLBACK4 ROLES
Most teams do not staff every role a standard names. The same steps, the same controls, on the team you actually have.
CRO / Board Risk5 STEPS COVERED
- Govern1Register AI-orchestrated intrusion and AI-system compromise as named enterprise risks (NIST AI RMF Govern)
- Govern2Set autonomy limits and decision rights across the six domains (IMDA MGF v1.5 dim 1)
- Govern6Singapore CII operators: initiate board-level AI-threat review per CSA CII directive (5 May 2026)
- Govern7FROM GRC / ComplianceAssemble the regulator evidence pack: MAS AIRG readiness (post-consultation, not final), IMDA MGF v1.5 mapping, CTM status for CII-touching capability
- Recover7Approve control and policy updates, close the loop into Govern
SOC Manager7 STEPS COVERED
- Identify4FROM Threat Intel LeadMap catalogued threats to your estate using MITRE ATLAS and OWASP LLM and Agentic Top 10
- Identify6FROM Threat Intel LeadRun tabletop against the selected threat class with domain owners observing (this is where roles learn each other's steps)
- Detect2FROM Tier 1 AnalystTriage: validate the signal, enrich with agent identity, tool, prompt hash, operatorM-B2-04
- Detect6Declare incident, open the bridge, assign responders
- Respond1FROM Incident ResponderLead containment per CoSAI AI IR Framework V1.0: disable agent, operate kill switch
- Recover1FROM Incident ResponderRecover agents to clean baselines, validate trust boundaries before re-enable
- Recover6Run lessons-learned, update runbooks and the detection backlog
Detection Engineer3 STEPS COVERED
- Detect1Detections live: rate signature over 1,000 req/sec, expired-CSP-domain egress, agent config changeM-A4-01, M-B1-03, M-B5-02
- Detect4FROM Threat HunterPivot on indicators: illogical tool-execution chains, token-usage spikes (M-Trends 2026 heuristics)
- Recover5Convert incident learnings into new detections and close coverage gaps
IAM / Identity Owner5 STEPS COVERED
- Identify2Enumerate machine and agent identities and their privileges
- Protect3Least privilege per tool, short-lived per-tool credentials, external authorisation (target system enforces, not the LLM)M-B2-01, M-B2-02, M-B5-01
- Protect4Human-in-the-loop gates for consequential actions (IMDA MGF v1.5 dim 2)M-B2-03
- Detect5Confirm agent identity anomaly, prepare token and grant revocationM-B5-02
- Respond2Revoke agent tokens, rotate credentials, disable OAuth grantsM-B5-01
CISO / Head of Security12 STEPS COVERED
Last resort. These steps reach no selected role in their fallback chain.
- Govern3Publish NIST AI RMF plus IR 8596 crosswalk (IR 8596 is Initial Preliminary Draft, flag as draft-dependent)
- Govern4Require AI use-case intake to cite AI 600-1 risks and Manage actions
- Govern5FROM Data Owner / PrivacyClassify data reachable by agents and set data-handling limits
- Identify1FROM Cloud Security EngineerInventory agentic platforms and every MCP server in the toolchainM-B4-02
- Identify5FROM Data Owner / PrivacyMap which agents can read sensitive data and CRM records
- Protect6FROM Network / Security EngineerEgress allow-lists deny-by-default, DNS blocking of consumer LLM endpoints where policy requiresM-A3-01, M-B1-03
- Detect3FROM Tier 2 AnalystScope tool-invocation chain across SIEM, EDR, and cloud, confirm exfil pathM-A4-02
- Respond3FROM Cloud Security EngineerIsolate affected workloads and cloud planes, block egress pathsM-B4-03
- Respond4FROM Network / Security EngineerBlock C2 and exfil domains, enforce egress cutoffM-A3-03
- Respond6FROM Data Owner / PrivacyAssess data exposure and breach-notification obligations
- Respond7Own regulator notification and external comms decisions
- Recover4FROM Data Owner / PrivacyConfirm data integrity, execute privacy notifications if required
Role widgets
One dashboard card per selected role, sharpened for the current threat.
Incident RACI and handoffs
Activities derived from class A4. R responsible, A accountable, C consulted, I informed. This is the live-incident assignment view; steady-state accountability lives in the framework document's standing RACI.
| Activity | CSF | CISO | CRO / Board | SOC Mgr | T1 | T2 | Hunter | IR | Det Eng | Cloud Sec | Net Eng | Data Owner | IAM |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Register AI risk and set autonomy limits | Govern | R | A | R | I | I | I | I | I | I | I | I | C |
| Inventory affected assets, agents, MCP, identities | Identify | I | A | C | R | R | |||||||
| Harden runtime and identity for this vectorA delegated: App Owner to Cloud Sec | Protect | I | C | R | R | R | |||||||
| Build and tune detections for the threat signature: Thousands of agent requests per second from one identity | Detect | I | R | R | A | C | C | ||||||
| Triage and validate alerts | Detect | I | A | R | R | C | |||||||
| Contain and eradicate | Respond | I | I | R | A | R | R | R | |||||
| Assess data exposure and notification | Respond | C | I | R | A | ||||||||
| Recover to a clean baseline | Recover | I | A | R | C | ||||||||
| Lessons learned and control update | Recover | R | A | R | C | C | C | C | R | C | C | C | C |
Incident handoff sequence
Triage
T1
Investigate
T2
Contain
IR
Eradicate
IR
Recover
IR
Lessons learned
SOC Mgr
Threat-driven adaptation
Signal to anchor: Thousands of agent requests per second from one identity (M-A4-01).
Monitor and harden are control-backedInvestigate are hypotheses to testMitigate are response actions
Class A4AI as autonomous attack orchestrator (GTG-1002, GTG-2002)
Identity
Monitor Single agent identity issuing thousands of requests per second
Harden Scoped per-tool credentials, external authorisation
Investigate Agent acting beyond human operational tempo
Mitigate Revoke tokens, disable agent
M-A4-01AML.TA0015
Network
Monitor Physically impossible request rates and multi-target fan-out
Harden Rate limiting on agent-initiated traffic
Investigate Map campaign breadth across targets
Mitigate Egress cutoff
M-A4-01
Data
Monitor Bulk access and exfil across many systems
Harden DLP and least data reach per agent
Investigate Determine blast radius and data classes
Mitigate Contain data paths, revoke access
M-A4-02
Cloud
Monitor Multi-source correlated intrusion across SIEM and EDR
Harden Cross-plane segmentation
Investigate Reconstruct autonomous tactical chain
Mitigate AI-assisted SOC response
M-A4-02M-A4-03
Assumptions and gaps
Stated so the reader can challenge them. First-run defaults apply where inputs were not provided.
Environment assumptions
- Hybrid cloud deployment model.
- SIEM present.
- EDR or XDR present.
- CI/CD pipeline present and in scope.
- Standard SOC tooling: SIEM plus EDR or XDR plus cloud logs.
- Tiered analyst model (T1/T2) shown as default; tierless SOCs should map T1/T2 steps to their analyst pool and deselect the tiers.
Delegation model (how lean orgs are handled)
- When a step's owning role is not selected, the step is never dropped. It cascades down a fallback chain to the next qualified selected role and renders with a "delegated from" tag.
- Fallback chains follow competence adjacency and are recommended defaults, not standards-derived. Organizations should override them to match their structure.
- CISO is the accountable owner of last resort. Deselecting CISO can leave steps unresolvable, and the flow flags this explicitly.
- Delegation load indicator: when one role absorbs 3 or more delegated steps in a single function, the flow recommends staffing or MSSP coverage. MAS AIRG proportionality permits lighter frameworks, not absent ownership.
- Delegated steps are equally mandatory. The Standard/Subtle display toggle changes emphasis only, never scope.
Currently delegating from
- Threat Intel Lead: steps cascade to Hunter first.
- Platform / IT Ops Owner: steps cascade to Cloud Sec first.
- Application Owner: steps cascade to AI Platform first.
Fact, consensus, hypothesis
- Fact: GTG-1002 is a catalogued, primary-sourced entry (Confirmed).
- Consensus: monitor and harden items map to named controls and standards.
- Hypothesis: investigate items are starting hypotheses, not confirmed findings.
- This class touches the Data domain, so a data-exposure and notification activity is included in the incident RACI.
Division of labor across views
- Tab A answers sequence: who acts in what order within each CSF function.
- Tab D answers incident assignment: R/A/C/I when the alarm is live.
- The standing accountability RACI (framework document) answers steady-state ownership.
Steady-state ownership //Steady-state ownership (who owns each domain year-round) lives in the framework document, Section 2.4.