| IT incident management is an area of IT service management (ITSM) in which the information technology team seeks to return a software application or network service to normal operations as quickly as possible after an unexpected event. A pro-active IT incident management strategy helps keep an organization prepared for unexpected hardware, software and security failings and reduces the duration and severity of disruption from such events. Help desk and incident management teams rely on a mix of tools to resolve incidents, including monitoring tools to gather operations data for root cause analysis. Most organizations use a support system, such as a ticketing system, for categorizing, prioritizing and documenting follow-up. Strategies for incident management may follow an established ITSM framework, such as IT infrastructure library (ITIL) or be based on a combination of guidelines and best practices established over time. ITIL incident management uses this workflow for efficient resolution: incident identification, logging, categorization, prioritization, response, diagnosis, escalation, resolution and recovery, and then closure. An incident manager enforces the proper incident response and management processes across the IT support and service delivery team or teams. The incident manager is also likely to act as a communication bridge between end users and technical specialists during disruptions. Support Levels IT incident management is normally separated into three levels of support. Level-one support typically provides basic-level support or assistance, such as password resets or computer troubleshooting. Level-one support involves incident identification, logging, prioritization and categorization, deciding to escalate to level-two support and incident resolution when appropriate. Level-two support goes through a similar workflow but is for more complex issues that need more skill or security access to complete. Major incidents are level-three support. This category includes incidents that might disrupt a business's operation and require an immediate response. |
1 comment:
Nice blog. Security incident management tools are becoming increasingly important as new regulations and legislation stipulate disclosure after security breaches. Thanks for sharing how to build best incident response framework for my enterprise.
Post a Comment