Overview
In the fields of computer security and information technology, computer security incident management involves the monitoring and detection of security events on a computer or computer network, and the execution of proper responses to those events. Computer security incident management is a specialized form of incident management, the primary purpose of which is the development of a well understood and predictable response to damaging events and computer intrusions.
Incident management requires a process and a response team which follows this process. In the United States, This definition of computer security incident management follows the standards and definitions described in the National Incident Management System (NIMS). The incident coordinator manages the response to an emergency security incident. In a Natural Disaster or other event requiring response from Emergency services, the incident coordinator would act as a liaison to the emergency services incident manager.
3 sources for this section
- 1Computer security incident management — Wikipedia, revision 1367219842
- 2"ISO 17799|ISO/IEC 17799:2005(E)". Information technology - Security techniques - Code of practice for information security management. ISO copyright office. 2005-06-15. pp. 90–94.
- 3"NIMS - The Incident Command System". National Incident Management System. Department of Homeland Security. 2004-03-01. Archived from the original on 2007-03-18. Retrieved 2007-04-08.
Preparation
Good preparation includes the development of an incident response team (IRT). Skills need to be used by the IRT would be, penetration testing, computer forensics, network security, etc. The IRT should also keep track of trends in cybersecurity and modern attack strategies. A training program for end users is important as well as most modern attack strategies target users on the network.
5 sources for this section
- 1Computer security incident management — Wikipedia, revision 1367219842
- 4Johnson, Leighton R. (2014), "Part 1. Incident Response Team", Computer Incident Response and Forensics Team Management, Elsevier, pp. 17–19, doi:10.1016/b978-1-59749-996-5.00038-8, ISBN 978-1-59749-996-5, retrieved 2021-06-05
- 5"Computer Incident Response and Forensics Team Management". Network Security. 2014 (2): 4. February 2014. doi:10.1016/s1353-4858(14)70018-2. ISSN 1353-4858.
- 6"Cybersecurity Threat Landscape and Future Trends", Cybersecurity, Routledge, 2015-04-16, pp. 304–343, doi:10.1201/b18335-12, ISBN 978-0-429-25639-4, retrieved 2021-06-05
- 7Wills, Leonard (27 February 2019). "A Brief Guide to Handling a Cyber Incident". American Bar Association.
Identification
This part of the incident response plan identifies if there was a security event. When an end user reports information or an admin notices irregularities, an investigation is launched. An incident log is a crucial part of this step. All of the members of the team should be updating this log to ensure that information flows as fast as possible. If it has been identified that a security breach has occurred the next step should be activated.
3 sources for this section
- 1Computer security incident management — Wikipedia, revision 1367219842
- 8Information technology. Security techniques. Information security incident management, BSI British Standards, doi:10.3403/30268878u, retrieved 2021-06-05
- 9Turner, Tim (2011-09-07), "Our Beginning: Team Members Who Began the Success Story", One Team on All Levels, Productivity Press, pp. 9–36, doi:10.4324/9781466500020-2, ISBN 978-0-429-25314-0, retrieved 2021-06-05
Containment
In this phase, the IRT works to isolate the areas that the breach took place to limit the scope of the security event. During this phase it is important to preserve information forensically so it can be analyzed later in the process. Containment could be as simple as physically containing a server room or as complex as segmenting a network to not allow the spread of a virus.
4 sources for this section
- 1Computer security incident management — Wikipedia, revision 1367219842
- 10"of Belgrade's main street. The event took place in absolute", Radical Street Performance, Routledge, 2013-11-05, pp. 81–83, doi:10.4324/9781315005140-28, ISBN 978-1-315-00514-0, retrieved 2021-06-05
- 11White, Mark D. (2013). "Why Choice Matters So Much and What Can be Done to Preserve It". The Manipulation of Choice. Palgrave Macmillan. pp. 127–150. doi:10.1057/9781137313577_7. ISBN 978-1-137-31357-7.
- 12Cichonski, Paul; Millar, Thomas; Grance, Tim; Scarfone, Karen (2012-08-06). Computer Security Incident Handling Guide (Report). National Institute of Standards and Technology.
Eradication
This is where the threat that was identified is removed from the affected systems. This could include deleting malicious files, terminating compromised accounts, or deleting other components. Some events do not require this step, however it is important to fully understand the event before moving to this step. This will help to ensure that the threat is completely removed.
6 sources for this section
- 1Computer security incident management — Wikipedia, revision 1367219842
- 13Borgström, Pernilla; Strengbom, Joachim; Viketoft, Maria; Bommarco, Riccardo (4 April 2016). "Table S3: Results from linear-mixed models where non-signficant [sic] parameters have not been removed". PeerJ. 4: e1867. doi:10.7717/peerj.1867/supp-3.
- 14Penfold, David (2000), "Selecting, Copying, Moving and Deleting Files and Directories", ECDL Module 2: Using the Computer and Managing Files, London: Springer London, pp. 86–94, doi:10.1007/978-1-4471-0491-9_6 (inactive 11 July 2025), ISBN 978-1-85233-443-7
- 15Gumus, Onur (2018). ASP. NET Core 2 Fundamentals : Build Cross-Platform Apps and Dynamic Web Services with This Server-side Web Application Framework. Packt Publishing Ltd. ISBN 978-1-78953-355-2. OCLC 1051139482.
- 16"Do the Students Understand What They Are Learning?", Trouble-shooting Your Teaching, Routledge, 2005-02-25, pp. 36–40, doi:10.4324/9780203416907-8, ISBN 978-0-203-41690-7, retrieved 2021-06-05
- 12Cichonski, Paul; Millar, Thomas; Grance, Tim; Scarfone, Karen (2012-08-06). Computer Security Incident Handling Guide (Report). National Institute of Standards and Technology.
The source notesEvidence & further reading16 sources
- Computer security incident management — Wikipedia, revision 1367219842 Wikipedia contributors · Reference source · accessed 2026-09-22
- "ISO 17799|ISO/IEC 17799:2005(E)". Information technology - Security techniques - Code of practice for information security management. ISO copyright office. 2005-06-15. pp. 90–94. iso.org · Reference source · link imported 2026-09-22
- "NIMS - The Incident Command System". National Incident Management System. Department of Homeland Security. 2004-03-01. Archived from the original on 2007-03-18. Retrieved 2007-04-08. web.archive.org · Reference source · link imported 2026-09-22
- Johnson, Leighton R. (2014), "Part 1. Incident Response Team", Computer Incident Response and Forensics Team Management, Elsevier, pp. 17–19, doi:10.1016/b978-1-59749-996-5.00038-8, ISBN 978-1-59749-996-5, retrieved 2021-06-05 dx.doi.org · Reference source · link imported 2026-09-22
- "Computer Incident Response and Forensics Team Management". Network Security. 2014 (2): 4. February 2014. doi:10.1016/s1353-4858(14)70018-2. ISSN 1353-4858. dx.doi.org · Reference source · link imported 2026-09-22
- "Cybersecurity Threat Landscape and Future Trends", Cybersecurity, Routledge, 2015-04-16, pp. 304–343, doi:10.1201/b18335-12, ISBN 978-0-429-25639-4, retrieved 2021-06-05 dx.doi.org · Reference source · link imported 2026-09-22
- Wills, Leonard (27 February 2019). "A Brief Guide to Handling a Cyber Incident". American Bar Association.