> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/online-courses/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/online-courses/cyber-incident-response/stages-of-incident-response/incident-identification/incident-response-classification-levels.md).

# Incident Response classification levels

Not all incidents are equal:

* Severity
* Priority
* Organization culture

## Severity levels

Often difficult to measure completely

May be frequently adjusted and IT landscape changes (cloud, etc)

Must include input from upper management and other parts of the organization

## Common methodology

#### Urgency

How quickly will the damage continue to grow while the incident is still ongoing?

#### Impact

How widely is the impact felt, how many users or customers are affected and what will be the cost of the impact?

Each urgency and impact have their own ratings, which are sometimes combined to calculate priority

## Include other data in criteria

Risk assessments already performed by IT risk group

Business Impact Analysis data

Disaster recovery

Business continuity
