Security Incident Management
Overview
End-to-end management of security incidents including initial report, severity classification, investigation coordination, resolution, and lessons learned. Primary agent: SEC-INCIDENT-001.
Triggers
- Security breach detected
- Unauthorized access attempt
- Property theft or damage reported
- Safety incident with security implications
- Emergency situation requiring security response
Steps
- Incident Registration → Log initial report with who/what/where/when
- Severity Classification → Classify as Low, Medium, High, or Critical based on impact
- Immediate Response → Assign security resources based on severity
- Investigation Coordination → Gather evidence, interview witnesses, review CCTV
- Resolution → Determine root cause, assign corrective actions
- Closure & Lessons Learned → Document outcomes and share with security team
Success Criteria
- Incidents registered within required timeframe
- Severity classification consistent and accurate
- Investigation completed within SLA
- All incidents closed with documented outcomes
Common Pitfalls
- Delayed reporting → Incidents not reported immediately
- Inconsistent severity classification → Similar incidents rated differently
- Missing evidence → Evidence not preserved promptly
- No lessons learned → Repeat incidents from unaddressed root causes
Cross-References
security-alert-system/SKILL.md— Alert generation for incidentssecurity-surveillance/SKILL.md— CCTV evidence for investigations