Skip to content

Security Incident

What is Security Incident?

An event that actually or potentially compromises the confidentiality, integrity, or availability of information or information systems.

Information Security

Each of these is named in at least one of the same controls as security incident. The number is how many controls name both.

What the standards actually require on security incident

Requirements naming security incident across 6 standards, quoted from the control text.

The CISO is fully aware of all cyber security incidents within their organisation.

ISM-0733 · The CISO is fully aware of all cyber security incidents within their organisation.
C5 (Germany)8 controls

Once an incident has been worked through, record the resolution as the contract requires and issue that report to the customers affected so they can acknowledge it or confirm the outcome.

C5-SIM-03 · Documentation and reporting of security incidents
CIS Controls v86 controls

Train workforce members to be able to recognize a potential incident and be able to report such an incident.

CIS-14.6 · Train Workforce Members on Recognizing and Reporting Security Incidents
ISO 27002:20226 controls

Requires information security incidents to be responded to in accordance with documented procedures, rather than improvised case by case.

iso-27002-2022::5.26 · Response to information security incidents

FIRST PSIRT (Product Security Incident Response Team) Services Framework v1.1 published December 2020. SCOPE: parallel to CSIRT Services Framework but focused on PRODUCT VENDORS + PRODUCT TEAMS handling vulnerabilities + incidents affecting their products + cu...

FIRST-PSIRT-Services · FIRST PSIRT Services Framework (2020) - Product Security Incident Response Team Service Catalog

A responsible entity must report a critical cyber security incident (with significant impact on availability) to the ACSC within 12 hours of becoming aware of the incident.

SOCI-S30BC · Notification of critical cyber security incidents (12 hours)

Questions people ask about security incident

What is Security Incident?
An event that actually or potentially compromises the confidentiality, integrity, or availability of information or information systems.
Why is Security Incident important for compliance?
Security Incident is a key concept in Information Security. Understanding security incident helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Incident?
Security Incident appears in the requirement text of Australian Information Security Manual, C5 (Germany), CIS Controls v8, ISO 27002:2022, FIRST CSIRT Services Framework and Standards. Across these standards we have identified 45 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Incident?
Explore our compliance framework pages to see how security incident applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Incident applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.