Incident Response
What is Incident Response?
The organised approach to addressing and managing a security breach or cyberattack. Includes preparation, identification, containment, eradication, recovery, and lessons learned.
Related terms
Frameworks that govern incident response
What the standards actually require on incident response
Requirements naming incident response across 6 standards, quoted from the control text.
Provide IR support resource (help desk, support group) for incident handling assistance.
IR-7 · Incident Response Assistance →Requires an incident response support resource that forms part of the incident response capability and gives system users advice and assistance on handling and reporting incidents.
NIST800-IR-7 · Incident response assistance →Specific personnel are designated to be available on a 24/7 basis to respond to suspected or confirmed security incidents.
12.10.3 · 24/7 incident response coverage →Incident response plan for operational disruptions. Control from IEC 62443 framework, domain: IEC 62443: Incident Response & Recovery.
IEC62443-16 · Incident response plan for operational disruptions →Provide IR support resource (help desk, support group) for incident handling assistance.
IR-7 · Incident Response Assistance →Incident response plan for operational disruptions. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.
ISO27019-16 · Incident response plan for operational disruptions →Questions people ask about incident response
What is Incident Response?
Why is Incident Response important for compliance?
What concepts are related to Incident Response?
Which compliance frameworks address Incident Response?
Where can I learn more about Incident Response?
See how Incident Response applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.