# Connect delivery to the SOC and SIRT

Taiga Learning · Worksheet
https://taiga.training/en/lessons/security-operations/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Distinguish SOC monitoring from SIRT incident coordination.
- Prepare a useful security incident handoff.
- Connect containment, recovery, and corrective engineering.

## Exercise
Use the fictional token incident in this lesson. Write a handoff with facts, uncertainties, affected identities, preserved evidence, containment options, and decision owners. Do not include a token value.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
Security response needs defined authority, evidence, and handoffs. A development platform does not replace the organization’s SOC or incident response team.

## Sources
- [NIST: Incident Response Recommendations, SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final)
- [FIRST: CSIRT Services Framework](https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1)
- [Taiga: Shared responsibility](https://tai.ga/en/trust/shared-responsibility/)
- [Taiga docs: Audit log](https://docs.tai.ga/administration/audit-log/)

This worksheet supports learning. Completing it does not itself authorize a production change.
