Annex A 5.24–5.28

Security incident register

Report, triage, contain, and learn from security incidents, the ISO 27001 Annex A 5.24–5.28 workflow, and the record a SOC 2 auditor expects.

Start free See pricing
Security incident register walkthrough
app.keelgrc.com/incidents
Program
Security incidents
2
Open
1
Investigating
14
Resolved
3.2d
Avg time to resolve
IncidentSeverityStatusOwnerDetected
Phishing led to credential exposureHighInvestigatingSecOps2d ago
Misconfigured storage bucketMediumContainedPlatform5d ago
Laptop lost in transitLowResolvedIT team3w ago

When something goes wrong, an auditor doesn’t just want to know it happened. They want to see how you handled it. Keel’s incident register runs the ISO 27001 Annex A 5.24–5.28 workflow end to end: report the incident, set its severity, record how you contained it, work out the root cause, and capture the lessons learned, then raise a corrective action so the fix is tracked to closure.

Incidents get handled in Slack and forgotten

The response happens in a channel and a call, and once it’s over there’s no durable record: no severity, no containment notes, no root cause, no follow-up. Then a SOC 2 or ISO 27001 auditor asks to see your incident log, and there isn’t one.

What security incident register does

A real incident record

Capture each incident with a severity (low → critical), an owner, when it was detected, and what happened, so there’s a durable, timestamped record instead of a lost thread.

Work the response lifecycle

Move an incident through open → investigating → contained → resolved → closed, posting timeline updates and recording the containment actions you took along the way.

Root cause & lessons learned

Record why it happened and what you’ll change so it doesn’t recur, the parts of Annex A 5.27 (“learning from incidents”) an auditor looks for.

Share status with affected clients

When an incident touches a customer, share a private, tenant-branded status page for that one incident: they see only the plain-language updates you publish, on your logo and brand color, with a live timeline, phase stepper, and severity. Each recipient gets their own link, and viewing it requires a one-time code emailed to that recipient, so a forwarded link never exposes the page. Recipients can acknowledge receipt, subscribe to updates, and save a branded PDF; you can set a link expiry and see who has viewed and acknowledged.

Raise a corrective action

Promote any incident into the CAPA register in one click, pre-filled from the incident and linked back, so the follow-up is tracked to closure with an effectiveness check.

At-a-glance posture

See how many incidents are open, how many are still being investigated, and how many high-severity incidents are live, the numbers you report to leadership.

Why it matters

  • Keep a durable, auditor-ready record of every security incident
  • Run a consistent report → contain → root-cause → close lifecycle
  • Turn an incident into tracked corrective action in one click
  • Keep affected customers informed on a private, verified status page
  • Answer “show me your incident log” with a yes

Get audit-ready, and prove it

Security incident register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

Which frameworks expect incident management?

ISO 27001 requires it across Annex A 5.24–5.28 (planning, assessment, response, learning, and evidence collection), and SOC 2 expects a documented incident-response process with records. One register in Keel covers both.

Can I keep affected customers updated during an incident?

Yes. Turn on client sharing for an incident and add each affected contact to mint them a private, per-recipient link to a tenant-branded status page for that one incident. They see only the plain-language updates you publish (never your internal notes), and opening the page requires a one-time verification code emailed to that recipient, so the link cannot be used by anyone it was not sent to. Recipients can acknowledge receipt, subscribe to updates, and save a branded PDF; there is no universal public status page.

What does the incident lifecycle look like?

Report → investigating → contained → resolved → closed, with fields for containment actions, root cause, and lessons learned captured as you go.

How does an incident connect to corrective action?

You can raise a nonconformity (CAPA) from any incident in one click. It’s created pre-filled from the incident and linked back, so the corrective action is tracked to closure with an effectiveness check.