Incident Escalation Procedure Prompt
Prompt
Create procedure for recognizing security-relevant incidents and escalating to security team while preserving evidence.
Why it works
Service desk as first responder can catch incidents early. Evidence preservation is critical for forensics.
Watch out for
Service desk may over or under-escalate. Non-trained investigation destroys forensic value.
Used by
IT & Ops Teams