Security Incident Management Runbook: Third-Party Incident

Author(s): Nitin Mukesh

  • Security Incident Management Runbook: Third-Party Incident

  • Security Incident Management Workflow: Third-Party Incident (Visio)

  • Security Incident Management Workflow: Third-Party Incident (PDF)

Incidents can be categorized into runbooks where a standardized response process is defined, eliminating inconsistency and ambiguity while increasing operational efficiency. Clearly document use cases that pertain to the incidents commonly faced by your organization.

Customize the third-party incident runbook by including the following sections for each single endpoint, multiple endpoints, and server infection:

  • Incident summary
  • Escalation process diagram
  • Detailed response procedures
  • Revision history