Escalation Criteria
Definition
The documented conditions that require an analyst to transfer an incident to a higher tier or to external stakeholders. Examples include: severity threshold breach, time elapsed without containment, involvement of executive accounts, and approaching regulatory notification deadlines.
- Trigger examples
- Severity breach, elapsed time, executive-account involvement
- Documented in
- Incident response plan
- Purpose
- Consistent handoff to a higher tier or stakeholders
Common questions
Why must escalation criteria be documented rather than left to individual analyst judgement?+
Documented criteria ensure incidents of a given severity are escalated consistently regardless of which analyst is on shift, reducing the risk that a serious incident is delayed by one person's inexperience or workload.
How do regulatory notification deadlines factor into escalation criteria?+
Many breach-notification laws impose fixed windows for informing regulators or affected individuals, so escalation criteria often include a time-based trigger to loop in legal and compliance teams early enough to meet those deadlines.
Related terms
- Contact Tree
- A structured list of individuals and teams to notify during an incident, showing the order of contact and the conditions under which...
- Handoff Package
- The bundle of information an analyst prepares before transferring an incident to a higher tier. Contents include incident ID, timeline, severity, containment...
- P1/P2/P3/P4 Severity Tiers
- A common four-level severity classification used in SLA structures. P1 (Critical) carries the shortest time windows; P4 (Low) carries the longest. The...
- Service-Level Agreement (SLA)
- A policy or contractual commitment defining how quickly the SOC must perform specific actions (acknowledge, escalate, contain, resolve) for incidents of each...
- SLA Breach
- An instance where a required action was not completed before its SLA timer expired. Each breach is recorded against the incident ticket...