Incidents¶
Path: /incidents

NIST 800-61 compliant incident management. Track security incidents from detection through post-incident review.
Key Elements¶
- Stats row — Total incidents, open count, breaches, and critical severity count.
- Filter tabs — All, New, Triaging, Active, Resolved, Closed.
- Severity dropdown — Filter by Critical, High, Medium, Low.
- Incident table — Number (INC-YYYY-NNN), title, severity, phase, status, and reported date.
- Report Incident button — Create a new incident report.
Incident Phases (NIST 800-61)¶
- Detection — Incident is first identified.
- Analysis — Investigating scope and impact.
- Containment — Limiting the damage.
- Eradication — Removing the threat.
- Recovery — Restoring normal operations.
- Post-Incident — Lessons learned and documentation.
- Closed — Incident fully resolved and documented.
How to Report an Incident¶
- Click Report Incident.
- Enter title, description, category (phishing, unauthorized access, data breach, etc.), and severity.
- The incident gets an auto-generated number (INC-YYYY-NNN).
- Add timeline entries as the investigation progresses.
- Create tasks for responders.
- Move through phases as work progresses.