Security incident register
Report, triage, contain, and learn from security incidents, the ISO 27001 Annex A 5.24–5.28 workflow, and the record a SOC 2 auditor expects.
| Incident | Severity | Status | Owner | Detected |
|---|---|---|---|---|
| Phishing led to credential exposure | High | Investigating | SecOps | 2d ago |
| Misconfigured storage bucket | Medium | Contained | Platform | 5d ago |
| Laptop lost in transit | Low | Resolved | IT team | 3w ago |
When something goes wrong, an auditor doesn’t just want to know it happened. They want to see how you handled it. Keel’s incident register runs the ISO 27001 Annex A 5.24–5.28 workflow end to end: report the incident, set its severity, record how you contained it, work out the root cause, and capture the lessons learned, then raise a corrective action so the fix is tracked to closure.
Incidents get handled in Slack and forgotten
The response happens in a channel and a call, and once it’s over there’s no durable record: no severity, no containment notes, no root cause, no follow-up. Then a SOC 2 or ISO 27001 auditor asks to see your incident log, and there isn’t one.
What security incident register does
A real incident record
Capture each incident with a severity (low → critical), an owner, when it was detected, and what happened, so there’s a durable, timestamped record instead of a lost thread.
Work the response lifecycle
Move an incident through open → investigating → contained → resolved → closed, posting timeline updates and recording the containment actions you took along the way.
Root cause & lessons learned
Record why it happened and what you’ll change so it doesn’t recur, the parts of Annex A 5.27 (“learning from incidents”) an auditor looks for.
Share status with affected clients
When an incident touches a customer, share a private, tenant-branded status page for that one incident: they see only the plain-language updates you publish, on your logo and brand color, with a live timeline, phase stepper, and severity. Each recipient gets their own link, and viewing it requires a one-time code emailed to that recipient, so a forwarded link never exposes the page. Recipients can acknowledge receipt, subscribe to updates, and save a branded PDF; you can set a link expiry and see who has viewed and acknowledged.
Raise a corrective action
Promote any incident into the CAPA register in one click, pre-filled from the incident and linked back, so the follow-up is tracked to closure with an effectiveness check.
At-a-glance posture
See how many incidents are open, how many are still being investigated, and how many high-severity incidents are live, the numbers you report to leadership.
Why it matters
- Keep a durable, auditor-ready record of every security incident
- Run a consistent report → contain → root-cause → close lifecycle
- Turn an incident into tracked corrective action in one click
- Keep affected customers informed on a private, verified status page
- Answer “show me your incident log” with a yes
Get audit-ready, and prove it
Security incident register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
Which frameworks expect incident management?
ISO 27001 requires it across Annex A 5.24–5.28 (planning, assessment, response, learning, and evidence collection), and SOC 2 expects a documented incident-response process with records. One register in Keel covers both.
Can I keep affected customers updated during an incident?
Yes. Turn on client sharing for an incident and add each affected contact to mint them a private, per-recipient link to a tenant-branded status page for that one incident. They see only the plain-language updates you publish (never your internal notes), and opening the page requires a one-time verification code emailed to that recipient, so the link cannot be used by anyone it was not sent to. Recipients can acknowledge receipt, subscribe to updates, and save a branded PDF; there is no universal public status page.
What does the incident lifecycle look like?
Report → investigating → contained → resolved → closed, with fields for containment actions, root cause, and lessons learned captured as you go.
How does an incident connect to corrective action?
You can raise a nonconformity (CAPA) from any incident in one click. It’s created pre-filled from the incident and linked back, so the corrective action is tracked to closure with an effectiveness check.
Related features: Nonconformities & CAPA · Internal audits · CISA KEV catalog
Works with: ISO/IEC 27001 · SOC 2