Security Incident Report
Detects security incident reports containing forensic findings, root causes, and response gaps.
- Type
- keyword_list
- Confidence
- medium
- Confidence justification
- Medium confidence: keyword-based detection requires corroborative evidence for accurate identification.
- Jurisdictions
- global
- Regulations
- NDB Scheme (Cth), SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
- Frameworks
- CIS Controls, DISP, ISO 27001, NIST CSF, PCI-DSS, SOC 2
- Data categories
- security
- Scope
- narrow
- Risk rating
- 8
Should match
Security incident report received for review.— Exact 65 discovery probe - report phrase without response or root-cause findingsSecurity incident report: containment and recovery actions completed.— Exact 75 probe - incident-response evidence without a root-cause conclusionSecurity incident report: forensic analysis confirmed the root cause after containment.— Exact 85 probe - incident-response and root-cause evidenceSecurity incident report: forensic analysis and root cause analysis findings— Test match 1Indicators of compromise (IOC) identified: malware analysis and threat actor attribution— Test match 2Breach investigation: attack vector, compromise assessment, and incident forensics— Test match 3
Should not match
Security guard incident report— Non-match 1Minor traffic incident— Non-match 2Sample template for documenting a cyber event, causal findings, and containment actions.— Adjacent template language is not a populated cyber-incident recordThe public catalogue lists a cyber-event review document.— Public catalogue metadata has no security-incident primaryData breach report: OAIC notification sent to affected individuals.— Sibling breach-report language does not satisfy the security-incident primary
Known false positives
- Physical security or traffic incidents. Mitigation: Require cyber-specific terms like IOC, forensic analysis, or malware analysis.