Skip to content

Security Incidents

A security incident tracks a confirmed or suspected security event — phishing, malware, ransomware, denial of service, unauthorized access, data loss, or a policy violation — from detection through closure.

At minimum you need a Short description and a Category. Optional fields sharpen the picture: Subcategory, Severity (1 - High / 2 - Medium / 3 - Low) and Priority (1 - Critical through 4 - Low, tracked independently of severity), a Risk score, the Affected user and Affected CI, Source IP / Destination IP, a MITRE ATT&CK technique, Business impact (None through Critical), and Contact type (SIEM Alert, EDR Detection, Email Report, Phone, Analyst Triage, Threat Intelligence).

State is system-managed — read-only on the form — and advances only through the actions below, following a NIST-aligned SOC lifecycle:

State What it means Typical next action
Draft Logged, not yet triaged. Begin Analysis
Analysis Under investigation to determine scope and impact. Contain, or Mark False Positive
Contain Containment actions in progress (isolating hosts, blocking IPs). Eradicate, or Mark False Positive
Eradicate Removing the root cause. Recover
Recover Restoring affected systems to normal operation. Move to Review
Review Post-incident review. Close
Closed Terminal. Requires a resolution code and closure notes.

Mark False Positive is an early exit available from Analysis or Contain, closing the incident directly with just closure notes. Close requires a Resolution code — Resolved, False Positive, Duplicate, Risk Accepted, or Not Resolved — plus closure notes.

A Vulnerability Entry is the underlying vulnerability definition (typically a CVE), scored with a CVSS base score and qualitative CVSS severity (None through Critical), a Source (NVD, Third Party, Manual, Scanner), and a Solution.

State What it means Typical next action
New Newly identified. Review
Under Review Being assessed for applicability and scoring. Confirm
Confirmed Confirmed applicable, with CVSS scoring in place. Make Public
Public Publicly disclosed and actively tracked. Retire
Retired Terminal — no longer tracked.

A Vulnerable Item pairs a Vulnerability with the specific Configuration item it was found on, carrying a computed Risk rating (Critical / High / Medium / Low) and Risk score, a Source scanner (Qualys, Tenable, Rapid7, Manual), and remediation dates (First found, Last found, Due date).

State What it means Typical next action
Open Found, not yet triaged. Investigate, or Accept Risk
Under Investigation Confirming the CI is actually exposed. Plan Remediation, or Accept Risk
Awaiting Implementation Remediation planned, waiting on a patch or change. Resolve, or Accept Risk
Resolved Fix applied; Remediation status and closure notes captured. Close
Closed Terminal.
Risk Accepted Terminal — remediation deliberately deferred, with closure notes recording the sign-off.

Accept Risk is available from Open, Under Investigation, or Awaiting Implementation, and requires closure notes explaining the acceptance.

The launchpad Home dashboard (see the launchpad overview) gives an analyst their open-incident posture at a glance: by-priority, by-state, and by-category breakdowns, an SLA split, and a prioritized incident list. The Vulnerability Response overview does the same for the vulnerable-item queue: open items by risk rating, an SLA posture (overdue / due soon / on track), the CVEs affecting the most items, and remediation progress (Not Started / In Progress / Completed / Deferred) with a mean-time-to-remediate figure.