V and T. Verification and triage
STARTS WHENAn event of interest with evidence references.
DONE WHENContinue, stop, or defer, with a name and a time against it.
Verification establishes that the observed event is an incident, and one that requires a response. Triage ranks it against organizational objectives so the team works the most important incident first, which matters most when the impact is broad.
Verify before engaging the wider team. A declared incident has a cost of its own, pulling people off other work and slowing the systems under investigation, and that cost is worth paying only for real ones.
They run concurrently because both need the same insight and coordination from decision makers, and the outcome of both is the right resources on the right incident.
| Outcome | Use when | Then |
|---|---|---|
| Continue | Real, and it warrants a response | Escalate, engage the team and decision makers, triage |
| Stop | Not real | Close it and document why, for the next analyst who sees the same thing |
| Defer | Available information cannot settle it | Request more from the reporter or other sources, then decide again |
| # | Item |
|---|---|
| 1 | Incident record opened with identifier, title, handler, summary, classification, and evidence references |
| 2 | Indicators enriched with threat intelligence before the risk is rated |
| 3 | Initial risk rated on the four-level scale |
| 4 | Verification decision recorded with rationale, name, and time |
| 5 | Triage brief delivered, naming the single authorization required |
| 6 | Resource allocation agreed against everything else the team could be doing |
Watch out
- Documentation written after the fact is unreliable, and exact commands and timestamps are the first things to go. Open the record at verification and add to it as the response proceeds.