Incident management overview
Incident management is defined as the process of handling disruptive events in a structured manner to minimize the impact of a business process. In most of the organization, the responsibility of developing and testing incident management lies with the information security manager.
Objectives of incident management
Security managers need to understand the following objectives of the incident management process:
- Detecting incidents early
- Accurately investigating the incident
- Containing and minimizing damage
- Being able to restore services early
- Determining the root cause and addressing the same to prevent reoccurrence
All these activities will lead to minimizing the impact the incident has on the organization.
Phases of the incident management life cycle
It is very important to have a structured and well-defined process to manage the incident. The following life cycle is recommended for effective incident...