Chapter 15

Information Security Incident Management

Information Security Incident Management covers the analysis of data, so that you can improve your security incident detection and response capabilities.

Keywords

Security information event management; SIEM

image

Information security incident management is the next category.

Returning to that risk discussion, the umbrella under which all these controls are discussed, a pair of more in-depth questions arise:

What are the things that could go wrong?

What are the things that have already gone wrong?

As we have matured in detecting and responding to security incidents, we now have some data that we ...

Get Infosec Management Fundamentals now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.