Incident Management

While the occurrence of most incidents cannot be determined, they can be contained through an effective incident management process. Managing an incident starts with a policy –an incident management policy should be in place within the organization to direct staff on steps to take when an incident occurs. It is advised to map out the incident management process so that it is easy to follow, and all staff within the organization should be aware of the incident management process.

Control Objective

  • An incident management policy is documented, followed, reviewed, and updated  
  • The incident management process is tested regularly