This report explores different frameworks for handling information security incidents and proposes a model for Marriott International Inc. based on NIST 800-61. It discusses the relationship between incident response and other security processes, as well as the role of audit in providing assurance. The report concludes with recommendations for regular cyber security processes and employee training.