This is the second article in a series that aim to help organisations build and maintain their information security incident management and response capability.
In the previous article I introduced the issue of the general deficiency of effective incident management and response processes in many organisations. But what is a security incident? The short answer is: it depends! It is up to each organisation to define what kinds of events it determines to be a security incident.