Initial assessment to determine incident severity and appropriate response level.
Triage is the initial assessment of security events to determine severity, impact, and appropriate response. Triage answers: Is this a real incident? How severe? What's affected? What response is needed? Effective triage prevents over-response to minor events and under-response to serious incidents. Triage criteria should be defined in advance with clear escalation thresholds. SOC analysts perform continuous triage of security alerts.
Why It Matters
The DSC Perspective:
Good triage ensures appropriate response. Without effective triage, teams waste time on false positives or miss serious incidents. Define triage criteria and train responders on severity assessment.
