Information Security Incident Management
It is practically impossible for any organization to be able to work without any incidents. This is because neither people nor systems and technologies are perfect. Information security incident management refers to the steps taken to identify, manage, record, and evaluate security incidents and threats associated with information security. In an information technology infrastructure, this is a highly crucial step to take either after or before a cyber disaster takes place.
In this chapter, we will look at the entire information security incident management process, starting with what a security incident is and moving on to the step-by-step process of incident management. This will be followed by an evaluation of the effectiveness of the process by implementing the appropriate controls. We will also look into how incident management is formed in an organization and the related standards to look into.
Security incidents are inevitable and...