Deterministic Consent Gate: analytics remain disabled until explicit opt-in. No third-party trackers are loaded.

Capabilityspecificatie

Evidence capture for post-incident reviews

Threat Response Automation

Evidence capture for post-incident reviews defines a core capability outcome delivered by Threat Response Automation, including implementation intent and execution coverage.

NIS2DORA

Doel

Translate Threat Response Automation intent into a concrete capability stream that can be executed, measured, and accepted by the delivery team.

Scopecontext

Detection and response loop with automated triage and controlled containment.

Invoer

- Current-state architecture and operating model

- Approved bundle scope and target compliance obligations

- Delivery constraints, timeline, and responsible owners

Uitvoer

- Implemented capability increment with ownership mapping

- Execution notes and evidence pointers for review

- Operational handover requirements for production use

Acceptatiecriteria

- Capability can be demonstrated in a controlled walkthrough

- Owner, scope, and change boundaries are explicit

- Linked controls and evidence references are complete

Compliance-bewijsnotities

- [NIS2] Capability execution mapped in Threat Response Automation control evidence

- [DORA] Capability execution mapped in Threat Response Automation control evidence

Specificatieschema

Eigenaarsrol

Capability Stream Owner

Goedkeuringssign-off

Product owner and platform lead

Versioneringsbeleid

Revisioned per release with backward-compatibility notes

Reviewcadans

Sprint review and monthly capability maturity checkpoint

Bewijsretentie

Operational evidence retained for at least 12 months

Verplichte secties

- Capability objective and intended business outcome

- Technical scope and dependency matrix

- Implementation steps and ownership mapping

- Validation checklist and acceptance evidence

- Operational handover and support model