Triage is the initial assessment of a suspected incident, where responders quickly judge what they are dealing with, how serious it is, and what deserves attention first. Borrowed from emergency medicine, the term captures the core task: sorting many potential problems so that the most urgent receive the fastest response.
Within the Response phase, triage is the entry point. Not every alert is an incident, and not every incident is equally severe, so triage filters and ranks what arrives. A sound triage decision sets the tempo for everything that follows, directing scarce responder time toward the events most likely to cause harm and away from noise.
In practice, triage gathers initial context about an alert or report, confirms whether it represents genuine malicious or anomalous activity, and assigns a severity based on factors such as affected assets, potential impact, and scope. Responders classify the incident, decide whether to escalate, and route it to the right people. Clear severity definitions and criteria make these judgments consistent across analysts and under pressure. Good triage is fast but disciplined, balancing the need to act quickly against the risk of misjudging an event early.
References#
- NIST SP 800-61, Computer Security Incident Handling Guide
- SANS, Incident Handler's Handbook