unified
UC-IR-04 — Triage, categorize, and escalate reported security events
Triage every reported security event: validate that it is genuine, assess it against the agreed classification scheme, and decide whether to declare it an incident. Categorize and prioritize declared incidents by type, severity, and business impact, and escalate or elevate them to defined roles and management tiers according to documented thresholds and timeframes. Record triage decisions and their rationale in the incident system of record.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Incident Management & Response
- type
- corrective
- category
- administrative
Details
- unified_id
- UC-IR-04
- title
- Triage, categorize, and escalate reported security events
- statement
- Triage every reported security event: validate that it is genuine, assess it against the agreed classification scheme, and decide whether to declare it an incident. Categorize and prioritize declared incidents by type, severity, and business impact, and escalate or elevate them to defined roles and management tiers according to documented thresholds and timeframes. Record triage decisions and their rationale in the incident system of record.
- domain
- Incident Management & Response
- control_type
- corrective
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- RS.MA-02
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.MA-03
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.MA-04
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.25
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-IR-04 — Triage, categorize, and escalate reported security events mitigates No security monitoring or supervision of privileged activity
- strength
- related
- rationale
- Provides the documented process to supervise and escalate detected breaches to defined roles/tiers that the risk says is missing.
- UC-IR-04 — Triage, categorize, and escalate reported security events mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Validating and classifying events and declaring incidents is the assessment step that breach-notification-threshold decisions rest on.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-04 — Triage, categorize, and escalate reported security events
- Incident Management Lifecycle operates UC-IR-04 — Triage, categorize, and escalate reported security events
- UC-IR-04 — Triage, categorize, and escalate reported security events maps_to A.5.25 — Assessment and decision on information security events
- framework
- iso-27001
- control_id
- A.5.25
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-04 — Triage, categorize, and escalate reported security events maps_to RS.MA-02 — Incident Management: Incident reports are triaged and validated
- framework
- nist-csf-2
- control_id
- RS.MA-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-04 — Triage, categorize, and escalate reported security events maps_to RS.MA-03 — Incident Management: Incidents are categorized and prioritized
- framework
- nist-csf-2
- control_id
- RS.MA-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-04 — Triage, categorize, and escalate reported security events maps_to RS.MA-04 — Incident Management: Incidents are escalated or elevated as needed
- framework
- nist-csf-2
- control_id
- RS.MA-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Cybersecurity Incident Response operates UC-IR-04 — Triage, categorize, and escalate reported security events
- UC-IR-04 — Triage, categorize, and escalate reported security events mitigates No or insufficient incident-response procedures
- strength
- primary
- rationale
- Triage, classification, prioritization, and threshold-based escalation directly make incident handling consistent, prioritized, and timely.