D4IS Operations & Resilience

Incident Management

What It Is and Why It Matters

Incident management is the structured process of detecting, reporting, assessing, responding to, and learning from security incidents and service disruptions. For the CISA exam, this topic is important because auditors must evaluate whether organizations have effective incident management capabilities that minimize the impact of incidents, preserve evidence, and enable continuous improvement.

A security incident is any event that compromises the confidentiality, integrity, or availability of information or systems. This can range from malware infections and unauthorized access to data breaches and denial-of-service attacks. Service incidents, while not necessarily security-related, involve disruptions to normal service delivery that require structured response.

Effective incident management requires documented procedures, trained personnel, appropriate tools, clear communication channels, and coordination with internal and external stakeholders. Frameworks such as NIST SP 800-61 (Computer Security Incident Handling Guide) and ITIL provide detailed guidance on incident management processes.

Key Concepts and Terminology

Incident Response Phases

  • Preparation: Establishing the incident response capability before incidents occur. This includes developing response plans, forming an incident response team, deploying detection tools, and conducting training and exercises.
  • Detection and Analysis: Identifying that an incident has occurred through monitoring systems, alerts, user reports, or external notifications. Analysis involves determining the scope, severity, and nature of the incident.
  • Containment: Limiting the spread and impact of the incident. Short-term containment focuses on immediate actions (such as isolating affected systems), while long-term containment involves implementing temporary fixes that allow business operations to continue while a permanent solution is developed.
  • Eradication: Removing the root cause of the incident from the environment. This may involve removing malware, closing vulnerabilities, disabling compromised accounts, or rebuilding affected systems.
  • Recovery: Restoring affected systems and services to normal operation. This includes verifying that systems function correctly, monitoring for signs of recurrence, and confirming that business operations have resumed.
  • Post-Incident Review (Lessons Learned): Analyzing the incident after it has been resolved to identify what happened, why it happened, how effectively the response was handled, and what improvements should be made. This phase produces recommendations that strengthen the organization's defenses and response capabilities.

Incident Classification and Prioritization

Incidents should be classified by type (security breach, service outage, data loss) and prioritized by severity and business impact. Classification and prioritization determine the level of response effort and the escalation path. A critical incident affecting core business operations requires immediate executive-level attention, while a low-severity incident may be handled through standard support channels.

Incident Response Team

The incident response team (IRT), sometimes called a Computer Security Incident Response Team (CSIRT), is a cross-functional group responsible for managing incident response activities. The team typically includes members from IT security, IT operations, legal, communications, human resources, and relevant business units. Clear roles and responsibilities must be defined in advance.

Evidence Handling and Forensics

When incidents involve potential legal proceedings or regulatory investigations, proper evidence handling is critical. This includes maintaining a chain of custody, creating forensic images of affected systems, preserving logs and artifacts, and documenting all actions taken during the response. Evidence that is not properly handled may be inadmissible in legal or regulatory proceedings.

Escalation Procedures

Escalation procedures define when and how incidents are elevated to higher levels of authority or expertise. Functional escalation involves bringing in additional technical specialists, while hierarchical escalation involves notifying senior management or the board when the incident exceeds defined thresholds.

How This Appears on the CISA Exam

Incident management questions on the CISA exam typically focus on:

  • The proper sequence of incident response phases (preparation, detection, containment, eradication, recovery, lessons learned).
  • The priority of actions during an active incident (containment often takes precedence over investigation in the early stages).
  • The importance of the post-incident review and its role in continuous improvement.
  • Evidence preservation and chain of custody requirements.
  • Identifying the appropriate first action when an incident is detected.

Study Tips

  • Memorize the incident response phases in order and understand what activities occur in each phase.
  • Remember that containment comes before eradication; you must stop the bleeding before fixing the wound.
  • The post-incident review (lessons learned) is essential, not optional; exam questions often test this.
  • Understand the importance of evidence handling, especially the chain of custody, for incidents that may involve legal action.
  • Know the difference between functional and hierarchical escalation.

Related Subtopics

  • Security operations center (SOC) management
  • Threat intelligence and information sharing
  • Digital forensics fundamentals
  • BCP/DRP integration with incident response
  • Regulatory notification requirements for breaches
  • SIEM and log management

Ready to Test Your Knowledge?

Practice exam questions on Incident Management and other IS Operations & Resilience topics.

Start Practicing Free