Give the incident a stable identifier and identify the log owner, access classification, time zone, and system of record. Capture the original event report, detection and reporting times, validation, incident decision, category, severity, affected assets and services, coordinator, assigned responders, hypotheses, decisions, actions, results, communications, evidence references, recovery checks, conclusion, and follow-up owners.
Use one append-only chronology. Each entry should contain an entry identifier, timestamp and time source, author or system, entry type, factual description, confidence or uncertainty where relevant, related asset or service, decision or action owner, approval, result, and links to supporting records. Preserve original timestamps and separate observed facts from assumptions and later corrections.
The event report should capture when, what, how, and, if known, why the event occurred; the reporter; initial affected components; business impact; and any identified vulnerability. If the event becomes an incident, add the incident category, affected information, hardware, software, communications, documentation, or processes; recovery cost where the organization tracks it; actions taken, planned, and outstanding; internal and external notifications; resolution; and conclusion. Mark unknown fields as unknown rather than guessing.