Incident Classification/Categorization
An information security manager needs to develop a process to classify incidents based on their criticality. Classification helps the organization concentrate on areas of high risk and thus ensures optimum utilization of its limited resources.
The most effective method to deal with multiple incidents is to triage them by considering their criticality.
An information security manager needs to ensure the availability of a documented escalation process. The process should include criteria for the classification of events and the responsibility and authority for each type of event and set of actions along with the desired escalation to be implementeThe information security manager should design this process in consultation with senior management.
Help/Service Desk Processes for Identifying Security Incidents
It is of utmost importance to provide training to help desk personnel to enable them to distinguish between a normal event and a...