search menu icon-carat-right cmu-wordmark

Incident Management

White Paper
In this paper, the author describes incident management capability and what it implies for controlling security events and incidents.
Publisher

Software Engineering Institute

Abstract

An incident management capability is the ability to provide management of computer security events and incidents. It implies end-to-end management for controlling or directing how security events and incidents should be handled. This involves defining a process to follow with supporting policies and procedures in place, assigning roles and responsibilities, having appropriate equipment, infrastructure, tools, and supporting materials ready, and having qualified staff identified and trained to perform the work in a consistent, high-quality, and repeatable way.