home/glossary/Incident Handling

Incident Handling

nounid 2804·updated Aug 30, 2026
verified· unreviewed

The mitigation of violations of security policies and recommended practices.

MWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems3 citations · 3 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.06.0103.06.01 ¶ 203.07.04.c ¶ 2

Classifications

Entity Type

Process0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

80%llm-generatedllm:claude-haiku-4-5

Information Class

85%llm-generatedllm:claude-haiku-4-5

Variants

plural
Incident Handlings
possessive
Incident Handling's
pluralpossessive
Incident Handlings'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
Incident Handling is an action plan for dealing with intrusions, cyber-theft, denial of service, fire, floods, and other security-related events. It is comprised of a six step process: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
The mitigation of violations of security policies and recommended practices.
NIST SP 800-611 senseview framework →
§1
The mitigation of violations of security policies and recommended practices.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
The mitigation of violations of security policies and recommended practices.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.