CERT Coordination Center and Software Engineering Institute offer training courses. CERT’s Event Matrix gives a more defined role in what actions should be taken for different types of categories of events. For a “real incident”, then you can go through handling procedures, such as tracking and reporting (non-editable logs, etc.) For a real incident, you would want to do the forensics without getting into detail about specific OS’s/architectures. For example, I always found that the Event Matrix was a good tool for analysts.”]
Source: https://taosecurity.blogspot.com/2005/09/request-for-comments-on-cert-and-sei.html