Skip to content

Incidents

Last checked on

This is where you report security incidents, from a lost laptop to a leaked password, and take them step by step to resolution, with a timeline of what happened.

Why this protects your organisation

Handling an incident well limits the damage, and recording it teaches you something for next time. When a customer asks what happened and what you did about it, a timeline gives you an answer with dates and names rather than a recollection. ISO 27001 covers this in controls 5.24 to 5.28: being prepared, assessing incidents, responding to them, learning from them and keeping the evidence.

Steps

  1. Open Incidents in the Improve group and click New incident.
  2. Enter a title, choose the severity and check Detected on. Pick an owner, a responder and the involved assets, then click Create.
  3. Move the incident forward from the list with Start investigating, Mark as contained, Resolve and Archive. Each step asks when it happened.
  4. On the incident's page, use Add note under Timeline to record what happened, who wrote it and when.
  5. Create follow-up work under Tasks with Create task, or link an existing task.
  6. If something needs to change for good, click Open nonconformity at the top to follow the incident up as a nonconformity.

What you record

An incident has a Title, a Description and a Severity: Low, Medium, High or Critical. Detected on defaults to the moment you create it, but you can change it when you report an incident after the fact. The Owner is accountable for handling it, the Responder does the work. Under Involved assets you pick the laptops, systems or accounts that were affected.

Status and timeline

The status follows a fixed order: Open, Investigating, Contained, Resolved and Archived. At each step you fill in When, so the timeline matches what really happened, even if you enter it later. Every status change appears in the Timeline automatically, alongside the notes you add yourself. That gives you one view of what happened and when.

You can filter the list by Severity and Status. A high or critical severity gets a distinct colour, without any alarm.

From incident to improvement

An incident often needs more than putting out the fire. Open nonconformity creates a nonconformity in one go, carrying over the incident's title, description, date and owner. Click it again later and the button reads View nonconformity, taking you to the same record. Smaller follow-ups go under Tasks.

If it does not work

I cannot move an incident back to an earlier status

An incident only moves forward: open, investigating, contained, resolved, archived. That is why the list shows a single status button, for the next step. If you moved on too early, add a note to the timeline explaining what actually happened.

I do not see the New incident button

Owners and members can create and update incidents. An advisor can only do so once the workspace owner gives them edit rights for the Risks and controls module. Only an owner or member can delete an incident.

The involved assets are missing from the list

You can only choose assets that already exist under Assets in the Organisation group. Add them there first.

My timeline notes are not translated

The Translate into Dutch action only translates an incident's title and description, not its timeline. The translation is marked as machine translation and never replaces your own text.

Screens this is about

  • Incidents

Read next