Understanding security incidents and incident management
Figure 6.1 shows the representation of an occurrence of an incident. ISO 27000 defines a security incident as “a single or a series of unwanted or unexpected information security events that have a significant probability of compromising business operations and threatening information security” (https://www.iso.org/). There can be different sources of incidents, such as employees, clients, and third-party vendors. When an incident occurs or a weakness is discovered in a system or service, a mechanism must be established to ensure that an organization can respond quickly and effectively. The first thing that needs to be done to accomplish this goal is to devise a plan to handle any security problems that may arise.
ISO 27035 is the standard that talks in detail about information security incident management. Information security incidents and vulnerabilities can be identified, documented, assessed, responded to...