Terminology Index

Glossary

1801 terms

Open concept maps

Showing 865-896 of 1801 terms

I
32

Incident Lifecycle

The end-to-end stages of handling a security incident, preparation, detection and analysis, containment, eradication, recovery, and post-incident learning, that structure incident response from readiness through to lessons learned.

The incident lifecycle organizes incident response into phases: preparing in advance, detecting and analyzing an incident, containing it, eradicating the threat, recovering normal operations, and conducting post-incident review to learn. Widely based on standard models (such as NIST's), it gives blue teams a shared structure so nothing is skipped and each phase's output feeds the next. Understanding it is foundational to coordinated, effective incident response.

Introduced in: Blue Team Operations

Examples

  • Moving an incident through detection, containment, eradication, and recovery.
  • Preparing in advance so the response phases run smoothly.
  • Closing the loop with a post-incident review to capture lessons.

No related terms linked yet.