Appendix A. Sample Incident Report Form

The following fields represent some of the information that may be desired when receiving reports on suspicious activity. Collection of this information should be automated to track in a triage or trouble ticket system of some type and a database for storage, retrieval, and correlation of information. Whenever possible, it is strongly recommended that automated versions of the report include a pull-down or pick list from which answers may be selected. Pick lists greatly reduce the chance for data integrity to become an issue.

The following points should also be tracked by a trouble ticket system:

  • Incident handler entering the report

  • Date on which the report was entered or created

  • Date on which the report ...

Get Effective Incident Response Team, The now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.