Incident Identity & Workflow
Deduplication, audit trail, confidence scoring
Domain purpose
Deduplication, audit trail, confidence scoring
Fields, modifiers, profiles and tests
L0-F01Incident Uuid
Capture and validate the incident uuid element within the Incident Identity & Workflow layer.
L0-F02Reporting Timestamp
Capture and validate the reporting timestamp element within the Incident Identity & Workflow layer.
L0-F03Reporter Confidence Level
Capture and validate the reporter confidence level element within the Incident Identity & Workflow layer.
L0-F04Remediation Status
Capture and validate the remediation status element within the Incident Identity & Workflow layer.
L0-F05Deduplication Hash
Capture and validate the deduplication hash element within the Incident Identity & Workflow layer.
Implementation use
Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.
Practitioner and validation guidance
Establish a stable incident identity, auditable reporting time, remediation state and duplicate-detection mechanism. Preserve source-system provenance when records are merged.
- Validate the applicable profile and all conditional requirements.
- Retain source evidence, analyst rationale and transformation history.
- Record uncertainty and do not infer regulatory, certification or legal outcomes.