Incident Declaration
Definition
The formal decision, made during the Identification stage, that a detected event meets the organisation's criteria for a security incident. Declaration triggers the formal IR process and activates the incident response team.
- Stage
- Identification, in the PICERL model
- Trigger
- Detected event meets incident criteria
- Effect
- Activates formal IR process and team
- Framework
- SANS PICERL model
Common questions
What distinguishes a declared incident from a routine security alert?+
A routine alert is one of many events monitored day to day, while declaration is a deliberate decision that the event meets predefined severity or impact criteria, formally invoking the incident response team and process.
Why does the timing of incident declaration matter?+
Declaring too late delays containment and evidence preservation, while declaring too broadly can overwhelm response teams with false positives, so organisations define clear, documented criteria in advance to guide the decision.
Related terms
- After-Action Report (AAR)
- The formal document produced during Lessons Learned that records the incident timeline, decisions made, outcomes, and recommended improvements. The AAR drives updates...
- Containment Strategy
- A deliberate decision about how to limit an incident's spread, balancing the need to stop harm immediately against the risk of alerting...
- Eradication
- The phase in which the root cause of an incident is removed from the environment: deleting malware, patching exploited vulnerabilities, revoking compromised...
- NIST SP 800-61
- The US National Institute of Standards and Technology's Computer Security Incident Handling Guide. It defines a four-phase IR lifecycle: Preparation; Detection and...
- PICERL
- Acronym for the six SANS IR stages: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. The model is cyclical: the final stage...