Incident investigation occurs in the responding stage.
The responding stage of the cycle
The responding stage of the plan-protect-respond cycle is when an organization takes action to contain and mitigate the damage from a cyber incident. This includes investigating the cause of the incident, identifying affected systems, notifying affected users, and taking steps to prevent the incident from happening again. The planning stage is when an organization develops its cybersecurity strategy and plans for how it will respond to cyber incidents.
The protecting stage is when an organization implements its cybersecurity controls to protect its systems and data from cyberattacks.