workflow
Incident Reporting Channels & Spillage Response
Standing operator workflow that runs on the existing Control item for the incident-reporting and information-spillage control (UC-IR-03; framework nist-800-53 | iso-27001 | nis2, domains incident_management_response) — one recurring workflow instance per operating cycle attaches to and enriches that Control item, never a duplicate. It consumes the prior cycle's carry-forward from the same Control: the last-sweep timestamp from the previous instance's close-and-archive record, plus the still-open corrective-action and obligation Issues linked to the Control. In scope: intake acknowledgment and triage routing across the monitored mailbox, hotline, and service portal; spillage containment/eradication and obligation assessment; and maintenance of the authorities and special-interest-group (SIG) contact register — spanning NIST 800-53 IR-6, IR-7, IR-9, and PM-15; ISO 27001 A.6.8, A.5.5, A.5.6; and NIS2 reporting duties. Named deliverables: the deduplicated intake register and acknowledgment log, the batch routing decision, the spill case with verified eradication, the obligation assessment and exposed-personnel training evidence, the refreshed authority/SIG contact register, the capability-health dashboard, the corrective-action register, and the archived operating record. Out of scope: full containment, investigation, and forensic response for genuine security events — those are handed off to the detect-to-respond workflow (via the route_to_incident_triage routing decision plus the linked intake Issues) rather than duplicated here.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- compliance-legal
- domains
- controls
- standards
- nist-800-53
- iso-27001
- nis2
- sourceTemplateId
- workflow-library:controls-incident-reporting-spillage-response
- releaseId
- sha256:801f657afd613afa2d6a34b2a9198219da7d8f5923ef91d765537765855606a8
- canonicalUrl
- https://workflow-library.com/all/?w=controls-incident-reporting-spillage-response
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-IR-03
- UC-IR-11
- UC-GOV-23
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:801f657afd613afa2d6a34b2a9198219da7d8f5923ef91d765537765855606a8
Connections
- Incident Reporting Channels & Spillage Response operates UC-IR-11 — Respond to information spillage with defined procedures
- Incident Reporting Channels & Spillage Response operates UC-IR-03 — Provide channels to report events and obtain response help
- Incident Reporting Channels & Spillage Response operates UC-GOV-23 — Maintain contacts with authorities and special interest groups