General Principles of Incident Management

Introduction

In security operations, incidents are inevitable. From minor breaches such as access violations to major crises like violent protests, cyber intrusions, or armed attacks, incidents represent moments of high risk and potential disruption.

Clause 8.8.1 of ISO 18788:2015 establishes that organizations must implement structured incident management processes to ensure that events are managed lawfully, ethically, and effectively. The goal is not only to contain incidents but also to learn from them, reducing the likelihood of recurrence and strengthening resilience.

Why Incident Management Matters

  1. Operational Continuity
    • Incidents can disrupt security operations, client services, and community trust.
    • Effective management ensures rapid response and minimal downtime.
  2. Legal and Regulatory Compliance
    • Mismanaged incidents may result in violations of law or contract obligations.
    • Structured incident management provides evidence of compliance with ISO 18788, VPSHR, and local regulations.
  3. Human Rights Protection
    • Incidents often involve direct interactions with individuals.
    • Proper management ensures responses remain proportionate, lawful, and respectful of human rights.
  4. Risk Management Integration
    • Incident data feeds into the broader risk management framework (ISO 31000), enriching risk registers and improving preventive controls.
  5. Reputation and Trust
    • Clients, regulators, and communities judge a security provider by how it handles incidents.
    • Transparent and professional incident management enhances credibility.

General Requirements under ISO 18788 (Clause 8.8.1)

1. Establish a Structured Process

  • Organizations must design an Incident Management System (IMS) with defined steps:
    • Detection and reporting.
    • Response and containment.
    • Investigation and documentation.
    • Resolution and corrective action.
    • Lessons learned and improvement.

2. Clear Roles and Responsibilities

  • Personnel must know:
    • Who reports an incident.
    • Who coordinates response actions.
    • Who authorizes escalation or communication with external stakeholders.

3. Integration with Other Systems

  • Incident management must link to:
    • Risk management (Clause 6.1).
    • Communication processes (Clause 7.4).
    • Business continuity (Clause 8.1.4, ISO 22301).
    • Compliance obligations (ISO 37301).

4. Documentation and Auditability

  • Every incident must be logged, investigated, and archived.
  • Evidence must meet the Audit Evidence Reliability Model (AERM) to ensure credibility.

The Golden Thread: From Incident to Improvement

Clause 8.8.1 emphasizes that incident management is not just about reacting to events; it is about creating a learning loop:

  1. Capture - Collect accurate data on the incident.
  2. Analyze - Identify root causes (using RCA methodology, ICE control assessments, etc.).
  3. Correct - Apply corrective and preventive actions.
  4. Improve - Feed insights back into training, SOPs, and risk registers.

This ensures that every incident, whether minor or major, strengthens the SOMS and improves organizational resilience.

Documentation and Audit Evidence

Auditors will expect:

  • Incident Management Policy and Procedures.
  • Incident Logs or Registers.
  • Investigation Reports and Corrective Actions.
  • Training Records showing that personnel understand incident reporting.
  • Management Review Records demonstrating continual improvement.

Most reliable evidence (AERM): CCTV/bodycam footage, system logs, signed reports.
Moderately reliable: Supervisor statements, witness testimonies.
Least reliable: Verbal accounts without supporting documentation.

Conclusion

Incident management under Clause 8.8.1 of ISO 18788 is the backbone of operational resilience in security companies. It ensures that incidents are handled lawfully, proportionately, and systematically, with full accountability and respect for human rights.

By embedding incident management into the SOMS, organizations not only protect clients and personnel but also create a culture of learning, transparency, and continual improvement — key pillars of ISO 18788 certification and trusted security operations.