Keep this operating table in the evidence pack so each incident or continuity item has an owner, artifact, and decision point.
1 | Detect and triage | Monitoring owner | Log-source inventory, alarm record, alert follow-up note | Is this an abnormal event, possible critical security event, or confirmed incident?
2 | Classify and escalate | Incident manager | Severity assessment, reclassification history, escalation record | Which communication and reporting path applies?
3 | Respond and document | Security and operations owners | Containment, eradication, recovery, and decision records | Is damage minimized and is the response fully documented?
4 | Report and notify | Legal or compliance owner | Reporting analysis, authority or CSIRT notice if applicable, stakeholder notice if applicable | Does a significant-impact breach or adverse effect trigger notification?
5 | Recover and preserve evidence | Continuity owner | Continuity-plan activation, backup recovery evidence, record-retention controls | Was service restored within the continuity-plan delay and are records protected?
6 | Review and correct | Risk and control owners | Root-cause review, corrective actions, updated roles or procedures | Did the incident lead to a post-incident review and recurrence-risk measures?
7 | Close and reassess | Incident manager and service owner | closure approval, unresolved risk, notification follow-up, updated risk assessment and plan versions | Are all actions owned, and did the incident change service scope, suppliers, restoration assumptions, or reporting procedures?