The architect designs the Incident Response framework before incidents occur. The NIST SP 800-61 framework defines four phases: Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. The architect's role is to ensure Splunk supports every phase with data, dashboards, and automation.
Preparation includes building runbooks (step-by-step procedures) and pre-configuring Splunk SOAR playbooks that automate the first 5 minutes of response. The architect ensures that analysts have the enrichment data (asset info, identity data, threat intel) they need to make rapid containment decisions.