Violation Response
Having thought out responses to different scenarios before they happen can make a huge difference.
When a policy violation has been discovered the immediate response should already be define in the security policy.
How and why did the violation occur?
Take action based on that