Incident Management Modul
The Incident Management Module is an integral component of the Information Security Management System (ISMS) of the fuentis Suite. It enables organizations to systematically capture, manage, and track security incidents – a crucial building block for compliance with ISO 27001, NIS2, and other regulatory requirements.
Why is it relevant?
In today’s threat landscape, the ability to respond quickly and effectively to security incidents is business-critical. The module supports you in systematically managing incidents, fulfilling regulatory reporting obligations, and learning from incidents.
Core Concepts and Requirements
Section titled “Core Concepts and Requirements”Integration into the ISMS
Section titled “Integration into the ISMS”Incident Management is not a separate application, but a dedicated phase within the ISMS structure. Each incident is assigned to a specific entity, whereby all actions, visibilities, and treatments occur at the entity level. You can only access the Incident Management Module in the new trust-platform.
Core Functionalities
Section titled “Core Functionalities”1. Incident Reporting
Section titled “1. Incident Reporting”- Multiple Reporting Channels: Internal employees, external stakeholders, IT monitoring systems
- External Reporting Forms: Publicly accessible forms for persons without direct system access
- Email Verification: Protection against misuse through validation of external reports
- Categorization: Automatic or manual classification (e.g., phishing, ransomware, data leak)
- Prioritization: Severity assignment based on impact and probability
Note: You can of course create incidents directly in the user interface. However, you can also use the reporting portal and provide this link to your employees. This way, they don’t need to have their own user accounts. To do this, simply click on the “question mark” icon at the top right of the screen and copy the link for the incident portal from the slide-over that opens.

2. Incident Lifecycle Management
Section titled “2. Incident Lifecycle Management”Report Status Workflow:
- Unverified: Receipt of external report
- Submitted: Email-verified report
- Accepted: Accepted as actual incident
- False Positive/Spam: Rejected reports
Incident Status Progression:
- New Incident: Initially after acceptance
- Under Investigation: Active analysis in progress
- Ongoing: Confirmed incident, countermeasures in progress
- Escalated: Escalation to higher level (optional)
- Mitigated/Contained: Threat neutralized
- Resolved: Fully resolved
3. Workflow Management
Section titled “3. Workflow Management”- Assignment & Escalation: Clear responsibilities and escalation paths
- Status Tracking: Complete tracking of incident progress
- SLA Management: Monitoring of response and resolution times
4. Documentation & Audit Trail
Section titled “4. Documentation & Audit Trail”- Central Repository: Secure storage of all incident records
- Metadata Tracking: Timestamps, affected systems, actions performed
- ISMS Asset Linkage: Direct connection to affected TOGs (Target Object Groups)
NIS2 Compliance Features
Section titled “NIS2 Compliance Features”The module specifically supports the requirements of the NIS2 directive:
- Reporting Obligations: Predefined templates for regulatory notifications
- Deadline Monitoring: Automatic reminders for 24h/72h reporting deadlines
- Audit Trail: Complete documentation for compliance evidence
Implementation Aids and Best Practices
Section titled “Implementation Aids and Best Practices”Organizational Preparation
Section titled “Organizational Preparation”Define Roles and Responsibilities
Section titled “Define Roles and Responsibilities”Incident Manager
- Triage of external reports
- Status overview of all incidents
- Escalation decisions
Incident Handler
- Operational processing of assigned incidents
- Documentation of measures
- Status updates
Crisis Team (for Major Incidents)
- Strategic decisions
- External communication
- Business continuity coordination

Dashboard & Monitoring
Section titled “Dashboard & Monitoring”Recommended Dashboard Widgets:
- Incidents by Status: Overview of active incidents
- SLA Compliance: Adherence to response times
- Trend Analysis: Incident development over time
- Top Threat Categories: Most frequent incident types

Practice Tips
Section titled “Practice Tips”Practice Tip: Incident Response Playbooks
Create predefined playbooks for common incident types. These can be stored as templates in the system and activated when needed.
Practice Tip: Regular Exercises
Conduct quarterly incident response exercises. Use the test environment of the fuentis Suite for realistic simulations.
Practice Tip: Lessons Learned
Establish a structured process for post-incident reviews. The insights should flow directly into risk assessment and measure planning.
Glossary
Section titled “Glossary”BAO (Betriebliche Aufbauorganisation): Crisis management structure with strategic, tactical, and operational levels
CSIRT (Computer Security Incident Response Team): Specialized team for IT security incidents
False Positive: False alarm; reported incident that turns out to be harmless
Major Incident: Severe incident with significant impacts on critical business processes
MTTD/MTTR: Mean Time to Detect / Mean Time to Respond - KPIs for incident response
SLA (Service Level Agreement): Agreed response and resolution times
TOG (Target Object Group): Target object group in the ISMS; structural unit for asset grouping
Triage: Initial assessment and prioritization of incoming incident reports
Key Messages at a Glance
Section titled “Key Messages at a Glance”Integral ISMS Component: Incident Management is not a standalone solution, but deeply integrated into the ISMS structure
Compliance-Ready: Meets the requirements of ISO 27001, NIS2, and BSI IT-Grundschutz out-of-the-box
Structured Lifecycle: Clear status progression from report to closure with complete audit trail
Flexible Architecture: Scales from single tenants (Standard) to complex multi-entity scenarios (Professional/Enterprise)
Practice-Oriented: Supports real incident response processes with playbooks, escalation, and lessons learned integration