Information Security Incident
An information security incident is an event that actually or is about to harm the confidentiality, integrity, or availability of an organization's information or systems, without lawful authority. In practice, it is a change or occurrence in a system that negatively affects the organization. Not every event rises to the level of an incident, and how an organization classifies and responds to incidents typically depends on its own criteria and scope.
An information security incident is an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system. It is distinguished from a routine security event by its adverse impact, and it typically triggers an organization's incident response and incident management processes. In compliance contexts, the identification, handling, and reporting of such incidents are commonly governed by defined controls, though the specific thresholds, classification schemes, and response obligations vary by organization, applicable criteria, and scope.
Why it matters
Information security incidents are the events that compliance frameworks are ultimately designed to prevent, detect, and contain. The way an organization identifies, classifies, and responds to incidents is a direct indicator of the maturity of its security program, which is why both SOC 2 examinations and ISO/IEC 27001 certifications place significant weight on incident management processes. An incident is distinguished from a routine security event by its adverse impact: it actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or systems. Not every event rises to this level, and the thresholds used to make that distinction vary by organization.
Beyond the technical harm, incidents carry broader consequences. As CISA notes, cyber incidents can harm national security interests, foreign relations, and the economy, and can affect public confidence, civil liberties, and health. For an individual organization, an incident that is poorly handled can undermine customer trust, trigger contractual and regulatory reporting obligations, and expose weaknesses in the very controls that an auditor or certification body has been asked to assess.
It is important to keep the limits of compliance outcomes in view. A SOC 2 report attests only to the controls and the review period covered, and does not guarantee that an organization is free from incidents or breaches. Similarly, an ISO 27001 certificate covers only the defined scope of the information security management system. In both cases, the frameworks assess whether incident handling processes exist and, for SOC 2 Type II or an operating ISMS, whether they function as intended, not whether incidents will never occur.
Who it's relevant to
Inside Information Security Incident
Common questions
Answers to the questions practitioners most commonly ask about Information Security Incident.