Cybersecurity incident management is

[t]he processes for detecting, reporting, assessing, responding to, dealing with, and learning from cybersecurity incidents.[1]

Planning and preparing for a cybersecurity incident can be challenging for many organizations. When a cybersecurity incident occurs, an organization is required to take immediate action in order to mitigate threats to the confidentiality, integrity, and availability of its information assets. This requires effective deployment of resources and established communication strategies.

Some of the primary objectives of cybersecurity incident management include:

  1. Cybersecurity Best Practices Guide, at 34.

