Incident response is a structured process for detecting, assessing and containing security incidents and restoring normal operations. It includes preparation, detection, analysis, containment, eradication and lessons learned. The goal is to minimise damage, enable rapid recovery and continuously strengthen organisational resilience.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Incident response covers the coordinated actions an organization takes to contain a disruption, restore service, and learn from it.
The approach combines emergency management, IT service management, and later security operations. Guides such as NIST SP 800-61 and SRE practice frame it as a repeatable cycle of preparation, detection, containment, recovery, and review.
Think of a response as phases: stabilize the situation, limit spread, restore the service, and investigate what happened. A review turns observations into concrete improvements for the next event.
Actions limit damage and further spread.
The affected service is returned deliberately to a dependable state.
A review exposes causes and improvement actions.
Incident response creates shared priorities, clear communication, and learning beyond any single disruption.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.