Skip to content

Incident Management Modul

The Incident Management Module is an integral component of the Information Security Management System (ISMS) of the fuentis Suite. It enables organizations to systematically capture, manage, and track security incidents – a crucial building block for compliance with ISO 27001, NIS2, and other regulatory requirements.

Why is it relevant?
In today’s threat landscape, the ability to respond quickly and effectively to security incidents is business-critical. The module supports you in systematically managing incidents, fulfilling regulatory reporting obligations, and learning from incidents.

Incident Management is not a separate application, but a dedicated phase within the ISMS structure. Each incident is assigned to a specific entity, whereby all actions, visibilities, and treatments occur at the entity level. You can only access the Incident Management Module in the new trust-platform.

  • Multiple Reporting Channels: Internal employees, external stakeholders, IT monitoring systems
  • External Reporting Forms: Publicly accessible forms for persons without direct system access
  • Email Verification: Protection against misuse through validation of external reports
  • Categorization: Automatic or manual classification (e.g., phishing, ransomware, data leak)
  • Prioritization: Severity assignment based on impact and probability

Note: You can of course create incidents directly in the user interface. However, you can also use the reporting portal and provide this link to your employees. This way, they don’t need to have their own user accounts. To do this, simply click on the “question mark” icon at the top right of the screen and copy the link for the incident portal from the slide-over that opens.

Vorfall erstellen

Report Status Workflow:

  • Unverified: Receipt of external report
  • Submitted: Email-verified report
  • Accepted: Accepted as actual incident
  • False Positive/Spam: Rejected reports

Incident Status Progression:

  1. New Incident: Initially after acceptance
  2. Under Investigation: Active analysis in progress
  3. Ongoing: Confirmed incident, countermeasures in progress
  4. Escalated: Escalation to higher level (optional)
  5. Mitigated/Contained: Threat neutralized
  6. Resolved: Fully resolved
  • Assignment & Escalation: Clear responsibilities and escalation paths
  • Status Tracking: Complete tracking of incident progress
  • SLA Management: Monitoring of response and resolution times
  • Central Repository: Secure storage of all incident records
  • Metadata Tracking: Timestamps, affected systems, actions performed
  • ISMS Asset Linkage: Direct connection to affected TOGs (Target Object Groups)

The module specifically supports the requirements of the NIS2 directive:

  • Reporting Obligations: Predefined templates for regulatory notifications
  • Deadline Monitoring: Automatic reminders for 24h/72h reporting deadlines
  • Audit Trail: Complete documentation for compliance evidence

Incident Manager

  • Triage of external reports
  • Status overview of all incidents
  • Escalation decisions

Incident Handler

  • Operational processing of assigned incidents
  • Documentation of measures
  • Status updates

Crisis Team (for Major Incidents)

  • Strategic decisions
  • External communication
  • Business continuity coordination

Rollenverwaltung

Recommended Dashboard Widgets:

  • Incidents by Status: Overview of active incidents
  • SLA Compliance: Adherence to response times
  • Trend Analysis: Incident development over time
  • Top Threat Categories: Most frequent incident types

DSMS Dashboard

Practice Tip: Incident Response Playbooks
Create predefined playbooks for common incident types. These can be stored as templates in the system and activated when needed.

Practice Tip: Regular Exercises
Conduct quarterly incident response exercises. Use the test environment of the fuentis Suite for realistic simulations.

Practice Tip: Lessons Learned
Establish a structured process for post-incident reviews. The insights should flow directly into risk assessment and measure planning.

BAO (Betriebliche Aufbauorganisation): Crisis management structure with strategic, tactical, and operational levels

CSIRT (Computer Security Incident Response Team): Specialized team for IT security incidents

False Positive: False alarm; reported incident that turns out to be harmless

Major Incident: Severe incident with significant impacts on critical business processes

MTTD/MTTR: Mean Time to Detect / Mean Time to Respond - KPIs for incident response

SLA (Service Level Agreement): Agreed response and resolution times

TOG (Target Object Group): Target object group in the ISMS; structural unit for asset grouping

Triage: Initial assessment and prioritization of incoming incident reports

Integral ISMS Component: Incident Management is not a standalone solution, but deeply integrated into the ISMS structure

Compliance-Ready: Meets the requirements of ISO 27001, NIS2, and BSI IT-Grundschutz out-of-the-box

Structured Lifecycle: Clear status progression from report to closure with complete audit trail

Flexible Architecture: Scales from single tenants (Standard) to complex multi-entity scenarios (Professional/Enterprise)

Practice-Oriented: Supports real incident response processes with playbooks, escalation, and lessons learned integration