This document is a handbook for computer security incident response teams (CSIRTs) that provides guidance on forming and operating a CSIRT. It covers basic issues such as defining the CSIRT's mission, services, policies and quality assurance. It also provides detailed information on implementing an incident handling service and considerations for team operations such as security, continuity and staffing. The handbook is intended to help new and existing CSIRTs by sharing knowledge gained from the experiences of the authors and other experts in the field.