Preparation begins before the alert. Approve the policy and plan, define event and incident criteria, appoint the incident management team, establish reporting channels and external relationships, prepare forms and technical support, train personnel, and exercise the arrangements. These controls determine who receives an event report and how quickly the organization can declare and handle an incident.
When an event arrives, preserve its source and time, validate it, and register it. The incident coordinator applies the prepared criteria, considers business and technical impact, decides whether the event is an information security incident, assigns priority, and activates the appropriate incident response team. An event that does not meet the criteria should still retain its assessment and disposition because later correlation can change the decision.
The intake source can be a user, contractor, supplier, external response organization, monitoring team, or automated sensor. Route every report to the defined point of contact, then to the incident coordinator. Branch explicitly to false alarm, normal operational handling, possible incident pending more facts, or confirmed incident. Give every branch an owner, record, next action, and condition for reassessment.