workflow
Incident Management Lifecycle
Run the enterprise incident management lifecycle on a single governed incident record — an Issue item created at intake that every step enriches (there is no separate Incident type; the workflow instance anchors to that Issue). Open the record, analyze scope and impact, anchor the regulatory and remediation notification clocks to the detection date, contain/eradicate/recover, execute severity-based notifications, run lessons-learned and CAPA, classify the disposition, then prepare, hand off, and archive the governance package. Named deliverables: the scope-and-impact assessment, the root-cause analysis, the owned CAPA / remediation action plan, and the final evidence-and-decision governance package. In scope: operational and security incidents from detection through closure, including regulatory-notification clock management and corrective/preventive actions. Upstream: the incident originates on detection itself, but for a security-category incident this workflow consumes the containment-and-forensics handoff package produced by the Cybersecurity Incident Response workflow (linked in at the eradicate-and-recover step) rather than re-running SOC triage. Out of scope: real-time SOC triage and containment mechanics (owned by that Cybersecurity Incident Response workflow) and board-level reporting — the final governance package is handed off to the Quarterly Board & Audit-Committee GRC Reporting workflow, which reports the outcome without re-investigating.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- operations
- lineOfDefense
- operate
Details
- teams
- operations
- it
- compliance-legal
- domains
- grc
- standards
- nist-800-53
- iso-27001
- gdpr
- nydfs-500
- sourceTemplateId
- workflow-library:grc-incident-management-lifecycle
- releaseId
- sha256:77c1602449f9eb3f1137db475d9bf0562db8468f039c984fdbba64e37e5a422a
- canonicalUrl
- https://workflow-library.com/all/?w=grc-incident-management-lifecycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-IR-04
- UC-IR-05
- UC-IR-06
- UC-IR-07
- UC-IR-08
- UC-IR-09
- UC-IR-10
- UC-GOV-24
- UC-ASSET-11
- UC-BCDR-06
- UC-BCDR-08
- UC-BCDR-09
- UC-DATA-15
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:77c1602449f9eb3f1137db475d9bf0562db8468f039c984fdbba64e37e5a422a
Connections
- Incident Management Lifecycle operates UC-IR-05 — Assess and validate incident scope, impact, and magnitude
- Incident Management Lifecycle operates UC-BCDR-09 — Communicate recovery status to stakeholders
- Incident Management Lifecycle operates UC-IR-06 — Respond to, contain, and eradicate declared incidents
- Incident Management Lifecycle operates UC-IR-09 — Recover from incidents using defined initiation criteria
- Incident Management Lifecycle operates UC-ASSET-11 — Improve security plans and processes from operational lessons
- Incident Management Lifecycle operates UC-BCDR-08 — Declare recovery complete and set post-incident norms
- Incident Management Lifecycle operates UC-IR-04 — Triage, categorize, and escalate reported security events
- Incident Management Lifecycle operates UC-DATA-15 — Record and notify unauthorized disclosures of personal data
- Incident Management Lifecycle operates UC-IR-08 — Notify authorities and affected parties within deadlines
- Incident Management Lifecycle operates UC-IR-10 — Learn from incidents and communicate corrective actions
- Incident Management Lifecycle operates UC-BCDR-06 — Resolve operational incidents and eliminate root causes
- Incident Management Lifecycle operates UC-GOV-24 — Notify regulators of incidents and file required certifications
- Incident Management Lifecycle operates UC-IR-07 — Investigate incidents and preserve evidence and records