Short answer: After triage, the team confirms scope, enriches the record, assigns ownership, investigates, takes response actions, communicates status, verifies the outcome, and prepares closure and follow-up. Closure should be a decision based on evidence, not the end of an inactive ticket.
The middle of the workflow
- Confirm scope: Identify affected users, assets, services, data, suppliers, and related alerts.
- Enrich context: Add business impact, criticality, recent changes, and known dependencies.
- Assign ownership: Name one incident owner and separate technical, business, and communication tasks.
- Investigate: Record hypotheses, observed evidence, open questions, and changes in confidence.
- Respond: Track containment, eradication, recovery, approvals, results, and residual risk.
- Communicate: Record who needs an update, the decision owner, and the next communication point.
- Prepare closure: State what happened, what was affected, what remains open, and whether RCA or follow-up is required.
Keep the original alert and every material decision linked to the record. If work is split into child tickets, the parent should still show the overall state.
Why closure needs its own check
An incident may be technically quiet while evidence, customer communication, recovery testing, or follow-up work remains open. Record the closure reason, owner, date, residual risk, and any due follow-up before closing.
Practical example
After a suspicious sign-in is accepted as an incident, the team confirms affected accounts, assigns an owner, reviews identity and endpoint evidence, records containment, communicates impact, verifies recovery, and documents follow-up before closure.
FAQ
What is the purpose of the post-triage workflow?
It turns a signal into a managed record with confirmed scope, context, ownership, investigation, actions, communication, verification, and follow-up.
When is an incident ready to close?
When the owner has reviewed the outcome, current impact, evidence, decisions, unresolved risk, and required follow-up, not merely when activity stops.
Sources and further reading
- NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
- NIST Cybersecurity Framework 2.0
