The organized approach to detecting, containing, eradicating, and recovering from security incidents, and learning from them.
Incident response is the structured handling of security incidents. A common lifecycle runs from preparation, through detection and analysis, containment, eradication, and recovery, to a lessons-learned review.
A documented incident response plan with defined roles and communication paths lets an organization react quickly and consistently under pressure, limiting damage and meeting reporting obligations.