From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,100 courses taught by industry experts.

Reporting and documenting incidents

Reporting and documenting incidents

- [Instructor] Communication is an essential part of cybersecurity incident response efforts. Incident response teams must notify key stakeholders about the incident, provide updates, and maintain permanent records of security investigations. There are three important components to incident reporting. The first is notification, ensuring that everyone who needs to know about an incident is aware that an incident response effort is underway. The second is realtime updates, ensuring that those who need to be familiar with the response efforts are kept informed along the way. And the third is documentation, ensuring that there is a permanent record kept of the incident details and the response effort. Notification is a key responsibility of incident responders. As early as possible in an incident, responders should trigger notification of key personnel both inside the organization and external responders, if applicable. Every organization should have a specific list of individuals to…

Contents