Reporting incidents from SOW and SIR Workspace in DRIR
Summarize
Summary of Reporting incidents from SOW and SIR Workspace in DRIR
In the Zurich release, high-impact, high-urgency incidents created or escalated in the Service Operations Workspace (SOW) of Incident Management or in the Security Incident Response Workspace (SIR Workspace) are classified as major incidents. These major incidents are automatically logged and reported in the Digital Resilience Incident Reporting (DRIR) application to ensure timely and structured incident management and compliance.
Show less
Incident Reporting Workflow
- Incident Classification: Determine if the incident is a major ICT-related issue, security breach, or operational payment problem. Automatically classify incidents involving malicious unauthorized network access as major.
- Case Creation: Generate a DRI case record capturing essential details such as case number, source, state, subtype, priority, and requester.
- Activity Tracking & Notifications: Document all related actions in the Activities panel and notify the DORA analyst via email to keep stakeholders informed.
- Reporting Milestones:
- Initial Report: Automatically generated within 24 hours of the incident’s major classification.
- Intermediate Report: Generated within 72 hours if the incident remains open, updating incident data and reviewing response steps.
- Final Report: Produced one month after classification, upon incident closure, including enriched notes and final updates.
- Response Activation and Review: Trigger and monitor appropriate response steps throughout the incident lifecycle.
Incident Reporting Timelines
The reporting process follows strict timelines from the moment an incident is classified as major:
- Initial Report: Within 24 hours
- Intermediate Report: Within 72 hours
- Final Report: Within 1 month
Case Generation in Digital Resilience Incident Reporting
When an incident is marked critical in the SOW of Incident Management or in the SIR Workspace, a corresponding case is automatically generated in the Digital Resilience Incident Reporting application. This ensures all major incidents are centrally tracked and reported following the prescribed workflows, supporting compliance and effective incident resolution.
When a high-impact, high-urgency incident is created or an existing incident is marked as high priority in the Service Operations Workspace (SOW) of Incident Management or Security Incident Response Workspace (SIR Workspace), it is classified as a major incident. These major incidents are then logged and reported in the Digital resilience incident reporting application.
Incident reporting workflow
The following example shows a sample workflow for reporting an incident in Incident Management.- Determine if the reported DRI case is a major ICT-related incident, a security breach, or an operational payment issue. Assess whether any critical services are impacted.
- If the critical services affected criterion is not met, the DRI case is not classified as major. If there is any report of malicious unauthorized access to the network and information systems, the incident is automatically classified as major.
- Create a DRI case record. The Details tab includes information such as the case number, source, state, subtype, priority, requester, and other relevant details. Review actions related to the case which are documented in the Activities panel on the Details tab.
- Notification: Send an email notification to the DORA analyst to update them on the progress of the case.
- Initial report: Automatically collect initial report data. Generate an initial report no later than 24 hours once the incident is classified as major.
- Response activation: Activate the response steps for the incident.
- Intermediate report: Review the incident report, if the incident has been open for more than three days. Update the incident data in the intermediate report, which is generated no later than 72 hours after the incident is classified as major.
- Response review: If the incident is still open, review the response steps.
- Final report: Verify if the incident is closed and enrich the notes in the record. Update the final report with the revised notes, which is generated one month after the incident is classified as major.
Incident reporting timelines
| Report type | Timeline (From the time the incident is classified as major) |
|---|---|
| Initial report | 24 hours |
| Intermediate report | 72 hours |
| Final report | 1 month |
Case generation in Digital resilience incident reporting
When an incident is marked as critical in the Service Operations Workspace of the Incident Management application as shown in the example, a case is generated in Digital resilience incident reporting.
The SIR Workspace deploys a similar workflow for reporting high-impact incidents which are then logged in Digital resilience incident reporting.