Specifikacia schopnosti
Evidence capture for post-incident reviews
Threat Response Automation
Evidence capture for post-incident reviews defines a core capability outcome delivered by Threat Response Automation, including implementation intent and execution coverage.
Ucel
Translate Threat Response Automation intent into a concrete capability stream that can be executed, measured, and accepted by the delivery team.
Kontext rozsahu
Detection and response loop with automated triage and controlled containment.
Vstupy
- Current-state architecture and operating model
- Approved bundle scope and target compliance obligations
- Delivery constraints, timeline, and responsible owners
Vystupy
- Implemented capability increment with ownership mapping
- Execution notes and evidence pointers for review
- Operational handover requirements for production use
Akceptacne kriterie
- Capability can be demonstrated in a controlled walkthrough
- Owner, scope, and change boundaries are explicit
- Linked controls and evidence references are complete
Poznamky ku compliance dokazom
- [NIS2] Capability execution mapped in Threat Response Automation control evidence
- [DORA] Capability execution mapped in Threat Response Automation control evidence
Schema specifikacie
Rola vlastnika
Capability Stream Owner
Schvalovaci sign-off
Product owner and platform lead
Politika verzovania
Revisioned per release with backward-compatibility notes
Rytmus revizie
Sprint review and monthly capability maturity checkpoint
Retencia dokazov
Operational evidence retained for at least 12 months
Povinne sekcie
- Capability objective and intended business outcome
- Technical scope and dependency matrix
- Implementation steps and ownership mapping
- Validation checklist and acceptance evidence
- Operational handover and support model