A.5.25 Assessment and Decision on Information Security Events
Control Objective
The organisation shall assess information security events and decide if they are to be categorised as information security incidents.
Policy Statement
anDREa systematically evaluates all anomalous security events to determine if they constitute an information security incident. The Management Team holds ultimate responsibility for assessing events, making triage decisions, and ensuring full documentation within the ticketing system.
Event Assessment and Triage Procedure
The transition from a detected event to a confirmed security incident follows a structured workflow:
- Triage and Evaluation: Upon detection or notification, the event is analyzed against defined impact criteria to determine its severity, scope, and potential threat to the myDRE platform.
- Categorization Decision: The Management Team formally determines whether the event qualifies as an information security incident.
- Documentation: All assessment criteria, discussions, and final triage decisions are recorded directly within the designated security ticket to maintain an auditable trail for compliance purposes.
For operational workflows and subsequent response steps, see:
- How to handle incident tickets for step-by-step ticketing and administration instructions.
- A.05.26 - Response to information security incidents for the containment and mitigation protocol.