This document outlines a framework for security incident response team services, including incident management, analysis, information assurance, situational awareness, outreach/communications, and capability building. It details the specific sub-functions and processes within each of these high-level service areas. For example, incident management includes incident handling, analysis, and mitigation/recovery, with processes like incident validation, tracking, collection, coordination, and containment. Information assurance encompasses risk management, compliance management, and technical security support.