Incident management and reporting
An incident is an event that could possibly violate information security. The violation may breach confidentiality, integrity, and the availability requirements of information assets. Primarily, incidents happen due to weaknesses in the systems and operational processes and procedures.
When a systematic and procedural way of managing incidents is established in an organization, then it is called incident management.
Incident management consists of incident reporting and response to such reports.
Incident reporting refers to the mechanism of reporting suspected weaknesses and incidents to the management by employees, contractors, and third-party users.
The examples of incidents
The following are some of the examples of incidents:
- Access violation is a type of incident where an unauthorized entity either tries to gain access to the system and/or successfully gains access.
- The malfunction of hardware and software could possibly affect the availability of the...