{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Incident Management & Response","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-04","description":"Triage every reported security event: validate that it is genuine, assess it against the agreed classification scheme, and decide whether to declare it an incident. Categorize and prioritize declared incidents by type, severity, and business impact, and escalate or elevate them to defined roles and management tiers according to documented thresholds and timeframes. Record triage decisions and their rationale in the incident system of record.","details":{"control_category":"administrative","control_type":"corrective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"RS.MA-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"RS.MA-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"RS.MA-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.5.25","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Triage every reported security event: validate that it is genuine, assess it against the agreed classification scheme, and decide whether to declare it an incident. Categorize and prioritize declared incidents by type, severity, and business impact, and escalate or elevate them to defined roles and management tiers according to documented thresholds and timeframes. Record triage decisions and their rationale in the incident system of record.","title":"Triage, categorize, and escalate reported security events","unified_id":"UC-IR-04"},"id":"uc:UC-IR-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-04","sourceIds":["iso-27001","nist-csf-2"],"sourceUrl":null,"title":"UC-IR-04 — Triage, categorize, and escalate reported security events","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e218b15613e6307c24893a88852e970f842530118f3ba27267d02532e781c17","properties":{"rationale":"Provides the documented process to supervise and escalate detected breaches to defined roles/tiers that the risk says is missing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1fa3413a85c8476db33505a72b6bc4e3e0bc810f8052cce0cc2dd32ea89d6e6f","properties":{"rationale":"Validating and classifying events and declaring incidents is the assessment step that breach-notification-threshold decisions rest on.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60d8993c00ee955e2796a9a9375e629870a45ccc13e7f5212d2625a257211cc4","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","targetId":"uc:UC-IR-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b29309f092408f29a7b36a1e6cc57e0fcd6900deb9ae3478f974b68a368d287","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","targetId":"uc:UC-IR-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7566c86da6687604708ae8825c0fd65a28909fb3e0c43ea698aedff05673ebe4","properties":{"control_id":"A.5.25","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-25-7dc7a20c.json","targetId":"ctrl:iso-27001:A.5.25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b464d48b16f3cacdcb27aadac378dfa65c894b60208897d83617e6265afb66f","properties":{"control_id":"RS.MA-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-ma-02-c3a85b31.json","targetId":"ctrl:nist-csf-2:RS.MA-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd5d175f5cdd0480478890a6999df03180026f6f391384887edb4926f6a578da","properties":{"control_id":"RS.MA-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-ma-03-01574f56.json","targetId":"ctrl:nist-csf-2:RS.MA-03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ce1b3788199a5c8c977b6651115ade64b1523f032ee255d1c47637a40846a1ef","properties":{"control_id":"RS.MA-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-ma-04-dd501891.json","targetId":"ctrl:nist-csf-2:RS.MA-04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec837bcc8234af719cea8e53ce450e58abd265a7e40ac6d8dff3eef18e90465c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","targetId":"uc:UC-IR-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f4247c5bc2f12bf3f2f2cbc55a22245d1b2457378c9648ea8c6c97461cf9536e","properties":{"rationale":"Triage, classification, prioritization, and threshold-based escalation directly make incident handling consistent, prioritized, and timely.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/risk-ir-no-response-procedures-90eb7ba1.json","targetId":"risk:ir-no-response-procedures","type":"mitigates"}],"schemaVersion":1}
