Incident Response — Election Security Glossary
19 election security terms in the Incident Response category, with definitions sourced from NIST, CISA, EAC, and 30+ authoritative documents.
Browse all 19 terms in Incident Response
Incident Handling
The mitigation of violations of security policies and recommended practices.
Incident Management
The management and coordination of activities associated with an actual or potential occurrence of an event that may result in adverse consequences to information or information…
Investigation
A systematic and formal inquiry into a qualified threat or incident using digital forensics and perhaps other traditional criminal inquiry techniques to determine the events that…
Recovery
The activities after an incident or event to restore essential services and operations in the short and medium term and fully restore all capabilities in the longer term.
Response
The activities that address the short-term, direct effects of an incident and may also support short-term recovery.
Response Plan
incident response plan.
Security Automation
The use of information technology in place of manual processes for cyber incident response and management.
By ESG Editorial Team · Drawing on NIST, CISA, the EI-ISAC, and 25+ sources on incident response
Incident response is the practice of detecting, containing, and recovering from security events. In election administration, it covers the full spectrum: a phishing email reported by a county employee, a website defacement, a denial-of-service attack on a results-reporting portal, a ransomware deployment against a county government network, or a physical incident at a polling place.
Why this category matters for election security is that no defense is perfect. The question is not whether an incident will occur but whether, when it does, the response is fast, effective, and well-documented. Election offices that plan and rehearse their response recover faster, communicate better, and preserve public trust.
Federal guidance from CISA, the FBI, and the EAC provides the technical and procedural framework. State fusion centers and the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC) support information sharing across jurisdictions. The goal is to ensure that no county, no matter how small, faces a serious incident alone.
The terminology in this category covers the lifecycle of an incident: detection, triage, containment, eradication, recovery, and post-incident review. The concepts here are practical. They describe the steps an election office takes when something goes wrong.
How These Terms Relate
These concepts together describe the discipline of incident response. The terminology here draws on the broader cybersecurity incident-response literature, but with election-specific adaptations. The unifying theme is that response is a process, not an event. A good plan is documented, rehearsed, and exercised before an incident occurs. A good response is coordinated, communicated, and reviewed. The election-specific challenge is operating under fixed legal deadlines: election day is not movable, and an incident on or before it requires a response that keeps the election on schedule.
Related categories
1,851 terms
The technical context in which most incidents occur.
Operational Security53 terms
The day-to-day practices that reduce incident frequency and severity.
Communications53 terms
The public messaging that accompanies incident response.
Auditing46 terms
The reviews that confirm incidents are fully resolved and lessons are learned.
Can't find the right category?
Search the full glossary, or browse every term alphabetically instead.