{"description":"Runs on the existing system item. Record an incident on a system, evidence containment against response targets, and determine root cause with preventive action. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-incident-response-incident-closure","source":"incident-response","target":"incident-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["incident-problem-management"],"controlVerbs":{"UC-BCDR-06":"operates"},"controls":["UC-BCDR-06"],"department":"it","domains":["controls"],"kind":"incident-problem-management","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:incident-problem-management"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-incident-problem-review","contentDigest":"sha256:93d0aa5a409d203e64d1562914362cc6b67fd832883fe53c57410d39b3caa247","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-cybersecurity-incident-response"}],"roles":[{"contribution":"expertise","description":"Incident commander. Record response and containment.","id":"reviewer-1","nodeIds":["incident-response"]},{"contribution":"approval","description":"Problem-management reviewer. Approve incident record.","id":"reviewer-2","nodeIds":["incident-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:incident-problem-management"}],"releaseId":"sha256:93d0aa5a409d203e64d1562914362cc6b67fd832883fe53c57410d39b3caa247","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-incident-problem-review"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-incident-problem-review","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Incident & Problem Management","nodes":[{"data":{"instructions":"**Objective**\nRecord response and containment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident ticket and its timeline, monitoring alerts or the reporting source, affected system and data inventory, the severity matrix, and regulatory notification thresholds.\n2. Use the incident timeline and ticket updates, system and access logs during the incident, containment actions and their timestamps, communications and notifications sent, and the response targets in policy.\n\n**Procedure**\n1. Establish detection time from the alert or report rather than from ticket creation, test the assigned severity against the matrix, identify data categories affected, and flag under-classification that would relax response targets.\n2. Reconstruct the timeline from logs rather than from ticket narrative, measure each interval against the target for the severity, confirm required notifications were sent inside their windows, and record evidence preserved for later analysis.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, detection time and source, systems and data affected, severity with matrix rationale, notification duties triggered, and classification challenges raised.\n2. Document response actions with timestamps, intervals measured against targets, containment status and its basis, notifications sent with recipients and times, evidence preserved, and targets missed. Also record response actions and timeline.\n\n**Exit criteria**\nIncident commander provides expertise: Detection time is evidenced independently of ticket creation, severity follows the matrix, and notification duties are identified before the response window closes. The timeline is reconstructed from logs, intervals are measured against severity targets, missed notifications are recorded as exceptions, and evidence is preserved rather than overwritten by recovery.","kind":"task","label":"Record response and containment","requiredApprovals":1},"id":"incident-response"},{"data":{"controls":["UC-BCDR-06"],"instructions":"**Objective**\nApprove incident record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the reconstructed timeline, system and change records preceding the incident, prior incidents with similar signatures, known problem records, and control failures the incident revealed.\n2. Review all stage records, detection evidence, severity rationale, measured intervals, notification evidence, root cause analysis, prior incident matches, and preventive actions with owners.\n\n**Procedure**\n1. Distinguish trigger from underlying cause, search prior incidents for the same signature before declaring a novel cause, identify which control should have prevented or detected it, and record undetermined causes as undetermined rather than plausible.\n2. Trace the timeline to log evidence, verify missed targets and notifications are recorded as exceptions, confirm preventive actions address the named control failure, and return trigger-only cause analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the root cause result and its evidence, prior incident matches, the control that failed to prevent or detect, preventive actions with owners and dates, and cause elements that remain undetermined.\n2. Capture the authorized reviewer, the summary, accepted root cause result, closure date, targets missed, control failures identified, preventive actions with owners and dates, and linked issues raised. Also record incident summary.\n\n**Exit criteria**\nProblem-management reviewer provides approval: An approver accepts that cause analysis distinguishes trigger from underlying cause and searched for recurrence, the failed control is named, and undetermined causes are stated rather than assumed. The authorized reviewer accepts the record as evidence the incident control operated, and closure implies no assurance that the underlying cause is remediated until preventive actions complete.","kind":"task","label":"Approve incident record","requiredApprovals":1},"id":"incident-closure"}],"sourceTemplateId":"workflow-library:controls-system-incident-problem-review"}
