This document provides a playbook for responding to denial of service (DoS) attacks with objectives, activities, and stakeholders for preparation, detection, remediation, and post-incident phases. The playbook outlines initial containment activities such as requesting traffic drops from internet service providers, filtering traffic, and patching vulnerabilities. It also describes reporting, investigation, containment, eradication, and post-incident review and reporting requirements.