Process for detecting, responding to, and learning from security and operational incidents.
Incident management is the process for handling events that disrupt normal operations or pose security threats. It covers detection (identifying incidents), triage (assessing severity), response (containing and resolving), communication (keeping stakeholders informed), and learning (improving from incidents). Security incident management specifically handles breaches, malware infections, and other security events. Effective incident management minimises impact and enables organisational learning.
Why It Matters
The DSC Perspective:
Incidents are inevitable—response quality determines impact. Have documented procedures, clear roles, and practiced response capabilities. Learn from incidents to prevent recurrence.
