GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INC-002 Incident Detection and Triage

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Processes and technical controls are in place to detect potential security incidents from multiple sources: automated monitoring alerts, internal reports, threat intelligence, and third-party notifications. Detected events are assessed against defined criteria to determine whether they qualify as incidents. Triage decisions are documented.

Rationale

Detection and triage are the entry points of incident response. Weak detection means incidents escalate unnoticed; weak triage means resources are misdirected.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (13)

SEF-06Event Triage Processesfull
SEF-06Event Triage Processesfull
HIPAA-164.308.a.5.ii.BProtection from Malicious Softwareinformative
HIPAA-164.308.a.6.iiResponse and Reportinginformative
5.25Assessment and decision on information security eventsfull
NIS2-Art.21.2.bIncident Handlinginformative
NIS2-Art.23.3Significant Incident Criteriainformative
NIS2-CIR-3.4Event Assessment and Classificationpartial
NIS2-CIR-Art.3Significant Incident Criteria for the Relevant Entitiesinformative
IR-4Incident Handlingpartial
IR-5Incident Monitoringfull
CC7.3Evaluates Security Eventsfull
CC7.4Responds to Identified Security Incidentsinformative

Evidence (2)

configurationtechnicalautomated

Security monitoring and alerting configuration showing automated detection rules are in place across monitoring sources to surface potential security incidents.

Example: SIEM detection rule configuration export (e.g., Splunk saved searches, Elastic Security rules, AWS GuardDuty findings configuration) showing enabled rules covering core incident types with alert routing to the incident response team

Test: Review the security monitoring configuration. Verify: (1) automated detection rules are enabled for common incident types; (2) rules cover multiple input sources (cloud platform logs, application logs, network logs, EDR); (3) alerts are routed to a monitored queue or on-call channel; (4) confirm a sample of real events in the last 30 days generated alerts as expected.

recorddocumentmanual

Triage decision records showing detected events were assessed against incident criteria and triage outcomes were documented.

Example: Incident tracking system (Jira, PagerDuty, or equivalent) records for the last 90 days showing events received from all detection sources, triage decision (incident/non-incident), decision rationale, and analyst name

Test: Query the incident triage records for the last 90 days. Verify: (1) events from all detection sources appear in the tracking system; (2) each event has a documented triage decision with rationale; (3) events triaged as incidents are escalated to incident records; (4) response SLAs for initial triage are documented and met.

Questions (2)

boolean

Are processes and technical controls in place to detect potential security incidents?

Detection capability should not rely solely on automated alerting. Internal reporting channels and mechanisms to receive third-party notifications are also required.

multi

Which incident detection sources are covered by your triage process?

Automated SIEM or monitoring platform alertsEDR or endpoint security tool alertsInternal employee or team reports (e.g. phishing reports, suspicious behaviour observations)Third-party security researcher or bug bounty notificationsThreat intelligence feedsCloud provider security notifications (e.g. AWS GuardDuty, GCP Security Command Center)Customer-reported incidentsNone of the above

Automated alerts alone are insufficient. A robust detection process includes internal reporting channels and the ability to receive and triage external notifications.