Skip to content

Incident

Quick Summary

Tracks security incidents and service outages from detection through resolution. Incidents carry severity levels, involve the Incident Response Team, and produce the audit trail required by FedRAMP, NIST SP 800-171, and DFARS.

An incident ticket is created when a security event, service outage, or other disruption requires coordinated investigation and response. Incidents may be raised manually by a team member or escalated in place from an alert after triage confirms a genuine event.

The ticket captures detection details, affected systems, severity, and whether sensitive data (such as CUI) is potentially involved. All actions taken during containment, eradication, and recovery are documented directly on the ticket through notes and attachments, creating the authoritative record for post-incident review and regulatory reporting.

Evaluation and Reporting

Every incident is evaluated to determine whether it affects, or is likely to affect, the confidentiality or integrity of federal customer data -- such incidents are FedRAMP Reportable Incidents. The evaluating responder records the reportability determination and assigns a Potential Agency Impact N-rating (PAIN); a reportable incident whose PAIN rating is not promptly estimated defaults to PAIN 5. The PAIN rating sets the reporting clocks: affected parties receive an Initial Incident Report, Ongoing Incident Reports, and a Final Incident Report on PAIN-keyed timeframes, tracked as OLAs on the ticket.

Every incident ends in an After Action Report -- root cause, lessons learned, and corrective actions authored on the incident record and approved by the After Action Report Approvers CAB before the incident resolves.

See the Incident Response policy for the reporting timeframes, PAIN defaults, and the FedRAMP Security Inbox obligations.

Compliance Context

Incident tickets support overlapping requirements across FedRAMP and CMMC:

Control Area Requirement
Incident Handling (FedRAMP IR-4) Implement an incident handling capability that includes preparation, detection, analysis, containment, eradication, and recovery
Incident Reporting (FedRAMP IR-6) Report incidents to appropriate authorities within required timeframes
Incident Monitoring (FedRAMP IR-5) Track and document incidents on an ongoing basis
Incident Response (CMMC IR.L2-3.6.1) Establish operational incident-handling capabilities
Incident Reporting (CMMC IR.L2-3.6.2) Track, document, and report incidents to designated officials
CUI Incident Reporting (DFARS 252.204-7012) Report cyber incidents involving CUI to DoD within 72 hours

See the Incident Response playbook for detailed procedures.