Incident Response
Incident Response
Session-1 baseline process:
- Detect suspicious login or policy violation.
- Record a security event.
- Revoke or isolate the affected session if needed.
- Expose the incident through the security overview.
- Prepare user notification flow in the next stage.
This runbook will expand once persistent incident tables and notification delivery exist.