Open and run an internal incident record
Give responders one current account of impact, roles, evidence, decisions, actions, recovery, and the next update.
- Preparation
- Start immediately after declaration and continue until the authorised incident lead closes recovery.
- Difficulty
- Advanced
- Task
- Coordinate incident response
Before you start
Get what you need before you start
- Use the organisation’s incident policy and emergency contacts.
- Identify qualified security, privacy, legal, insurance, technical, and communications owners as applicable.
- Have qualified owners choose an access-controlled incident system, evidence repository, retention period, audit requirements, and evidence-handling route.
- Use Jira Service Management only for assigned actions, states, and approvals when the organisation has approved it. Keep sensitive incident evidence in the approved evidence repository and link to it under existing access controls.
Steps
Work through the method
Use the listed inputs and tools. Check the evidence when you need to verify a step.
Declare and assign roles
Open a timestamped record in the approved incident system. Select qualified role groups from the organisation’s policy and this incident’s needs, such as leadership, incident handlers, technical specialists, legal or privacy, communications, affected asset owners, and relevant third parties. Record decision authority, responsibilities, observed impact, affected systems, confidence, and the next update time.
Why it matters: Explicit roles and observed facts reduce conflicting decisions while the situation changes.
- Input
- The detection record, incident policy, current responders, and observed service or security impact.
- Output
- A restricted incident record with roles, impact, confidence, scope, and next update.
Tools in this stepEvidence for this step
Buffer’s breach record shows containment, partner coordination, recovery checks, changing facts, remediation, and continuing updates.
Buffer: Lines 68–100, 108–128, and 129–160NIST says incident-response roles differ by organisation and incident, then gives adaptable examples across leadership, incident handlers, technical professionals, legal, public affairs, human resources, facilities, asset owners, and third parties.
National Institute of Standards and Technology: NIST SP 800-61 Rev. 3 PDF pages 13–16, section 2.2 “Incident Response Roles and Responsibilities”
Coordinate containment and evidence
Log each proposed containment action, authority, owner, time, expected effect, evidence to preserve, and risk in the approved incident system. Keep sensitive evidence in the approved repository and use restricted links. Require authorised human approval before execution.
Why it matters: Containment can destroy evidence, expand harm, or interrupt critical service when responders act from different assumptions.
- Input
- The incident record, technical evidence, qualified-owner advice, and containment options.
- Output
- An approved containment log with preserved evidence and checked effects.
Tools in this stepEvidence for this step
Buffer’s breach record shows containment, partner coordination, recovery checks, changing facts, remediation, and continuing updates.
Buffer: Lines 68–100, 108–128, and 129–160NIST SP 800-61 Rev. 3 integrates incident response with preparation, detection, response, and recovery risk management.
National Institute of Standards and Technology: NIST SP 800-61 Rev. 3 PDF pages 8–13, Executive Summary and section 2.1 “Incident Response Life Cycle Model”
Test recovery before restoration
Record restricted links to eradication or repair evidence, recovery criteria, validation owner, monitoring plan, rollback condition, and approval. Restore only after the authorised owners inspect and accept the evidence.
Why it matters: Service availability alone does not show that the incident cause is removed or operation is safe.
- Input
- Containment state, repair evidence, backups, validation checks, and recovery authority.
- Output
- A tested and approved recovery record with monitoring and rollback conditions.
Tools in this stepEvidence for this step
NIST SP 800-61 Rev. 3 integrates incident response with preparation, detection, response, and recovery risk management.
National Institute of Standards and Technology: NIST SP 800-61 Rev. 3 PDF pages 8–13, Executive Summary and section 2.1 “Incident Response Life Cycle Model”
Close updates and improvements
Confirm the final internal status, hand approved facts to Customer Support, preserve the record and evidence under the approved retention and audit rules, and assign post-incident actions with owners and dates.
Why it matters: Recovery leaves future risk when decisions and improvement work disappear after service returns.
- Input
- The complete incident record, approved communications facts, monitoring evidence, and open risks.
- Output
- A closure decision, communications handoff, preserved record, and owned improvement set.
Tools in this stepJira Service ManagementEvidence for this step
Buffer’s breach record shows containment, partner coordination, recovery checks, changing facts, remediation, and continuing updates.
Buffer: Lines 68–100, 108–128, and 129–160
Success checks
Check the result before you finish
- One restricted record holds current roles, facts, confidence, decisions, and timestamps.
- Sensitive evidence stays in the approved repository under defined access, retention, and audit rules.
- Qualified owners approve evidence handling, notification, containment, and recovery.
- Recovery criteria are tested before restoration closes.
- Customer Support receives approved facts and post-incident work has owners.
Failure modes
Watch for these problems
- Responders edit facts without timestamps. Restore an append-only decision and change record.
- A containment action lacks authority. Pause it and escalate through the authorised incident lead.
- Evidence moves through an unapproved tool. Stop and follow the qualified evidence-handling route.
- Responders copy sensitive evidence into an action ticket. Remove the copy, keep a restricted source link, and review access and retention with the qualified owner.
- Service returns and the incident closes without monitoring. Keep recovery open until the agreed checks pass.
Tools
Choose the tools you need
Tool
Jira Service Management
A request system with service spaces, work items, queues, assignment, workflow states, and approval steps.
Check fit, limits and pricingSources
Read the sources behind this practice
Check what each source supports and where the advice has limits.
- Buffer: Buffer security breach has been resolved — here is what you need to knowFirst-hand founder incident record · Published 26 October 2013
- National Institute of Standards and Technology: NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk ManagementUS government technical guidance · Published 3 April 2025
- Atlassian Support: Manage your incoming requests with queuesOfficial product documentation · Publication date unavailable