166 terms · 75/46/45
Defense № 020 · class: monitoring / response

Incident Response

A planned process of identifying, containing, eradicating, and recovering from cyber incidents.

Term

description · examples · notes

A planned process of identifying, containing, eradicating, and recovering from cyber incidents.

Description

Defined by an IR plan with roles, communication chains, and procedures.

Covers phases: preparation, identification, containment, eradication, recovery, lessons learned.

Tabletop exercises test team readiness before an actual incident.

Regulatory requirements (GDPR, NIS2) mandate having an IR plan.

What people often say

  • An IR plan that is not tested is just a document — regular exercises are mandatory.
  • Incident response is not just an IT task — it involves legal, PR, and management.

Covers / does not cover

Covers

  • Coordinated incident response
  • Communication procedures (internal and external)
  • Post-incident analysis and improvements

Does not cover

  • Attack prevention (other controls do that)
  • Automated detection (that is SIEM/EDR)
  • In-depth digital forensics (that is a separate discipline)

Mentioned in the news

Composite

Threats

reduces 7

Techniques

neutralizes 4

Techniques it neutralizes. Select one to open its page.