Incident handling is a structured process for detecting, prioritizing, escalating and resolving IT and operational incidents. It defines roles, communication channels, playbooks and metrics to reduce downtime and optimize recovery time. The approach integrates monitoring, incident management tools and post-incident reviews across teams and the organization.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
Incident handling brings together immediate activities to detect, contain, and communicate an ongoing or impending service incident.
It arose from the need to coordinate service disruptions under operational time pressure. ITSM established the incident-management framing, while SRE practice added technical response and learning from incidents.
Detect, stabilize, inform, restore, learn: confirm and classify the signal, limit impact, coordinate recovery, keep affected people informed, and record lessons for the next response.
A signal is confirmed and classified as a relevant incident.
Immediate actions limit impact before the full cause is known.
The service is deliberately returned to a dependable state.
Incident handling matters for critical services with high availability or security needs. Speed must be balanced with safe communication, clear roles, and later root-cause work.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.