Incident Category
What is Incident Category?
A classification system for organizing security incidents by type such as malware, phishing, data breach, or denial of service.
Terms that appear alongside incident category
Each of these is named in at least one of the same controls as incident category. The number is how many controls name both.
- incident response 3 shared controls
- post incident review 2 shared controls
- lessons learned 2 shared controls
Frameworks that govern incident category
What the standards actually require on incident category
Requirements naming incident category across 3 standards, quoted from the control text.
UR E26 Goals 4 (Respond) + 5 (Recover) require incident response + recovery capabilities. Incident Response Plan (IRP) covers: detection triggers + classification (safety-impact + business-impact);
IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons · IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned →Integrate log management with broader NIST family per NIST SP 800-92 Chapter 6 (Establishing and Maintaining Log Management Infrastructures) + cross-references throughout.
NISTSP92-8 · Integration with NIST SP 800-53 AU Family, SP 800-137 ConMon, SP 800-61 IR, and Maturity →Operate incident detection + response + customer notification + post-incident review + BCM per scheme + applicable regulation. Incident detection and classification must (a) implement SIEM + EDR + fraud detection + with open banking-aware correlation rules + (...
OPENBANK-8 · Incident Detection, Response, Customer Notification, Post-Incident Review, BCM →Questions people ask about incident category
What is Incident Category?
Why is Incident Category important for compliance?
Which compliance frameworks address Incident Category?
Where can I learn more about Incident Category?
See how Incident Category applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.