AuditRubric
rs-ma-2 critical Respond / Incident Management

Triage and validate incident reports

Not every alert or report is a real incident. Triage is the process of quickly determining whether a reported event is a genuine security incident, a false positive, or something benign. Without a structured triage step, teams either waste resources chasing noise or, worse, dismiss real attacks as false alarms. Consistent validation criteria reduce both over-reaction and under-reaction, and they build confidence in the detection pipeline over time.

Estimated effort: 3h
triageincident-managementvalidationfalse-positive
Complete first: rs-ma-1

Implementation steps

  1. 1

    Define triage criteria and severity thresholds

    Document the specific criteria that distinguish a confirmed incident from a false positive or informational alert. Include signal sources, minimum evidence thresholds, and which roles are authorized to confirm or dismiss a report.

    confluencenotiongoogle-docs
  2. 2

    Assign a triage analyst and conduct initial review

    Route each incoming report to a qualified analyst within the defined SLA. The analyst checks relevant logs, threat intelligence, and affected asset context to determine whether the event meets the incident declaration threshold.

    splunkelasticmicrosoft-sentinelcrowdstrike
  3. 3

    Record the triage outcome and rationale

    Document the triage decision, the evidence reviewed, and the analyst's reasoning in the incident tracking system. False positives should be tagged and fed back to tune detection rules. Confirmed incidents proceed to categorization.

    jiraservicenowpagerduty

Evidence required

Triage decision log

Records showing each reported incident was reviewed and a disposition was recorded with supporting rationale.

  • · SIEM alert tickets with analyst notes and confirmed/dismissed status
  • · ServiceNow or Jira incidents with triage fields populated
  • · SOC shift handover reports listing triage decisions

Documented triage criteria

A written procedure or runbook that defines how triage is performed, including severity thresholds and false-positive handling.

  • · IR playbook section covering triage steps
  • · Confluence or Notion page with triage decision tree
  • · SIEM playbook or alert handling SOP

Related controls