Security Orchestration, Automation, and Response platforms increasingly rely on machine-readable incident response playbooks, yet existing research commonly treats playbook generation and selection as separate tasks. This separation leaves the relationship between attack modelling, defensive knowledge, repository enrichment, and incident-time playbook selection insufficiently specified. We present a dual-phase framework that transforms attack-graph-derived incidents into provenance-rich, machine-readable playbook records and integrates them with heterogeneous community playbooks in a shared ontology-backed repository. The framework connects MITRE ATT&CK techniques, CVE evidence, digital artifacts, and MITRE D3FEND defensive knowledge, while retaining explicit provenance for generated content. At selection time, direct attack provenance and ontology-mediated semantic associations are combined with transparent multi-criteria decision-making and coverage-aware selection strategies. The evaluation provides technical and construct-level validation of the resulting pipeline, including deterministic generation, repository reduction, semantic integration, candidate retrieval, and reproducible ranking. The results show that repository enrichment expands the ATT&CK coverage reachable through the available playbook pool and that coverage-aware and portfolio-based objectives can exploit this enlarged candidate space more effectively than balanced single-playbook ranking. The study establishes a reproducible foundation for provenance-aware playbook decision support, while operational correctness, actionability, and expert validation remain outside its present scope.