workflow
Incident Management Lifecycle
Run the enterprise incident management lifecycle on a single governed incident record — an Issue item created at intake that every step enriches (there is no separate Incident type; the workflow instance anchors to that Issue). Open the record, analyze scope and impact, anchor the regulatory and remediation notification clocks to the detection date, contain/eradicate/recover, execute severity-based notifications, run lessons-learned and CAPA, classify the disposition, then prepare, hand off, and archive the governance package. Named deliverables: the scope-and-impact assessment, the root-cause analysis, the owned CAPA / remediation action plan, and the final evidence-and-decision governance package. In scope: operational and security incidents from detection through closure, including regulatory-notification clock management and corrective/preventive actions. Upstream: the incident originates on detection itself, but for a security-category incident this workflow consumes the containment-and-forensics handoff package produced by the Cybersecurity Incident Response workflow (linked in at the eradicate-and-recover step) rather than re-running SOC triage. Out of scope: real-time SOC triage and containment mechanics (owned by that Cybersecurity Incident Response workflow) and board-level reporting — the final governance package is handed off to the Quarterly Board & Audit-Committee GRC Reporting workflow, which reports the outcome without re-investigating.
Record JSON · Open in map · Data retrieval guide
Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- operations
- lineOfDefense
- operate
Details
- teams
- operations
- it
- compliance-legal
- domains
- grc
- standards
- nist-800-53
- iso-27001
- gdpr
- nydfs-500
- sourceTemplateId
- workflow-library:grc-incident-management-lifecycle
- releaseId
- sha256:20aa1196fd41fd8da8b2cc442bbe1cbd788a452ae14194b5904a5f87559fc9ed
- canonicalUrl
- https://assureswarm.com/workflows/all/?w=grc-incident-management-lifecycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-IR-04
- UC-IR-05
- UC-IR-06
- UC-IR-07
- UC-IR-08
- UC-IR-09
- UC-IR-10
- UC-GOV-24
- UC-ASSET-11
- UC-BCDR-06
- UC-BCDR-08
- UC-BCDR-09
- UC-DATA-15
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:20aa1196fd41fd8da8b2cc442bbe1cbd788a452ae14194b5904a5f87559fc9ed
Connections
- Incident Management Lifecycle operates UC-IR-05 — Assess and validate incident scope, impact, and magnitude
- Incident Management Lifecycle operates UC-BCDR-09 — Communicate recovery status to stakeholders
- Incident Management Lifecycle operates UC-IR-06 — Respond to, contain, and eradicate declared incidents
- Incident Management Lifecycle operates UC-IR-09 — Recover from incidents using defined initiation criteria
- Incident Management Lifecycle operates UC-ASSET-11 — Improve security plans and processes from operational lessons
- Incident Management Lifecycle operates UC-BCDR-08 — Declare recovery complete and set post-incident norms
- Incident Management Lifecycle operates UC-IR-04 — Triage, categorize, and escalate reported security events
- Incident Management Lifecycle operates UC-DATA-15 — Record and notify unauthorized disclosures of personal data
- Incident Management Lifecycle operates UC-IR-08 — Notify authorities and affected parties within deadlines
- Incident Management Lifecycle operates UC-IR-10 — Learn from incidents and communicate corrective actions
- Incident Management Lifecycle operates UC-BCDR-06 — Resolve operational incidents and eliminate root causes
- Incident Management Lifecycle operates UC-GOV-24 — Notify regulators of incidents and file required certifications
- Incident Management Lifecycle operates UC-IR-07 — Investigate incidents and preserve evidence and records