Security Incidents
A security incident tracks a confirmed or suspected security event — phishing, malware, ransomware, denial of service, unauthorized access, data loss, or a policy violation — from detection through closure.
Creating a security incident
Section titled “Creating a security incident”At minimum you need a Short description and a Category. Optional fields sharpen the picture: Subcategory, Severity (1 - High / 2 - Medium / 3 - Low) and Priority (1 - Critical through 4 - Low, tracked independently of severity), a Risk score, the Affected user and Affected CI, Source IP / Destination IP, a MITRE ATT&CK technique, Business impact (None through Critical), and Contact type (SIEM Alert, EDR Detection, Email Report, Phone, Analyst Triage, Threat Intelligence).
States
Section titled “States”State is system-managed — read-only on the form — and advances only through the actions below, following a NIST-aligned SOC lifecycle:
| State | What it means | Typical next action |
|---|---|---|
| Draft | Logged, not yet triaged. | Begin Analysis |
| Analysis | Under investigation to determine scope and impact. | Contain, or Mark False Positive |
| Contain | Containment actions in progress (isolating hosts, blocking IPs). | Eradicate, or Mark False Positive |
| Eradicate | Removing the root cause. | Recover |
| Recover | Restoring affected systems to normal operation. | Move to Review |
| Review | Post-incident review. | Close |
| Closed | Terminal. Requires a resolution code and closure notes. | — |
Mark False Positive is an early exit available from Analysis or Contain, closing the incident directly with just closure notes. Close requires a Resolution code — Resolved, False Positive, Duplicate, Risk Accepted, or Not Resolved — plus closure notes.
Vulnerabilities
Section titled “Vulnerabilities”A Vulnerability Entry is the underlying vulnerability definition (typically a CVE), scored with a CVSS base score and qualitative CVSS severity (None through Critical), a Source (NVD, Third Party, Manual, Scanner), and a Solution.
| State | What it means | Typical next action |
|---|---|---|
| New | Newly identified. | Review |
| Under Review | Being assessed for applicability and scoring. | Confirm |
| Confirmed | Confirmed applicable, with CVSS scoring in place. | Make Public |
| Public | Publicly disclosed and actively tracked. | Retire |
| Retired | Terminal — no longer tracked. | — |
Vulnerable items
Section titled “Vulnerable items”A Vulnerable Item pairs a Vulnerability with the specific Configuration item it was found on, carrying a computed Risk rating (Critical / High / Medium / Low) and Risk score, a Source scanner (Qualys, Tenable, Rapid7, Manual), and remediation dates (First found, Last found, Due date).
| State | What it means | Typical next action |
|---|---|---|
| Open | Found, not yet triaged. | Investigate, or Accept Risk |
| Under Investigation | Confirming the CI is actually exposed. | Plan Remediation, or Accept Risk |
| Awaiting Implementation | Remediation planned, waiting on a patch or change. | Resolve, or Accept Risk |
| Resolved | Fix applied; Remediation status and closure notes captured. | Close |
| Closed | Terminal. | — |
| Risk Accepted | Terminal — remediation deliberately deferred, with closure notes recording the sign-off. | — |
Accept Risk is available from Open, Under Investigation, or Awaiting Implementation, and requires closure notes explaining the acceptance.
The security dashboards
Section titled “The security dashboards”The launchpad Home dashboard (see the launchpad overview) gives an analyst their open-incident posture at a glance: by-priority, by-state, and by-category breakdowns, an SLA split, and a prioritized incident list. The Vulnerability Response overview does the same for the vulnerable-item queue: open items by risk rating, an SLA posture (overdue / due soon / on track), the CVEs affecting the most items, and remediation progress (Not Started / In Progress / Completed / Deferred) with a mean-time-to-remediate figure.