# Incident Response
**Source:** https://glossary.keenfunnel.com/terms/incident-response
**Language:** German

---

## Technische Erklärung

An incident-response capability defines roles, severity, evidence handling, communications, legal and regulatory escalation, containment options, recovery criteria, and post-incident improvement. NIST integrates incident response into broader cybersecurity risk management rather than treating it as an isolated sequence.

## Geschäftliche Relevanz

Prepared response reduces downtime, data loss, confusion, and notification delays. It helps organisations make defensible decisions under pressure and restore trusted operations.

## Implementierungsbeispiel

After detecting stolen credentials, a response team disables sessions, preserves logs, scopes affected systems, rotates secrets, communicates with stakeholders, restores services, and tracks corrective actions.

## Einschränkungen und häufige Missverständnisse

A written plan is insufficient without exercises, telemetry, authority, supplier coordination, and tested recovery. Premature containment can destroy evidence, while delayed action can increase impact.

## Themen

Cybersicherheit Systemarchitektur

## Quellen

NIST SP 800-61 Rev. 3 — Incident Response — NIST CSF 2.0 — https://www.nist.gov/cyberframework

## Besprechen Sie Ihre Systeme

Benötigen Sie Hilfe bei der Implementierung oder Bewertung dieses Konzepts? Keenfunnel entwirft vernetzte KI-, Automatisierungs- und Datensysteme.

Discovery-Session buchen