Incident Response & Operations

Incident Response Incident Log · 72-Hour Clock · Chain of Custody

The Incident Response module is your operational log for security incidents. from detection through containment, eradication, recovery, and reporting. Every step is timestamped and attributed, creating the chain-of-custody documentation that satisfies DFARS reporting requirements and demonstrates operational IR capability to assessors.

72hr DFARS reporting clock tracked
IR.L2 3.6.1 and 3.6.2 satisfied
Full Chain of custody
The problem this solves
IR.L2-3.6.1 requires an operational incident-handling capability. not just a written plan. The distinction matters. An assessor verifying this practice looks for evidence that your capability has been exercised: incident records, response timelines, personnel roles documented in action, and reporting history. A plan that has never been used satisfies the documentation requirement while failing the operational one. The module creates that operational record as incidents are handled, not after the fact.

Incident Lifecycle and 72-Hour Reporting

Each incident record moves through defined phases: Detection, Analysis, Containment, Eradication, Recovery, and Closure. At each phase you document actions taken, personnel involved, systems affected, and evidence collected. The structured lifecycle ensures nothing is skipped between phases and creates the comprehensive incident record that supports both internal review and external reporting.

DFARS 252.204-7012 requires reporting cyber incidents to DoD via DIBNet within 72 hours of discovery. The module tracks the discovery timestamp, calculates the reporting deadline automatically, and records when the DIBNet submission was made and by whom. The 72-hour clock is visible on open incidents from the moment a record is created. removing any ambiguity about whether the reporting window has been met.

Dashboard Requirements Evidence POA&M Reports
1TEN Incident Response module showing the incident log from detection through 72-hour DoD reporting and closure

Incident Log and History

The incident log maintains a complete history of all incidents. open, closed, and archived. Each closed incident record includes the full lifecycle documentation: what was detected, how it was analyzed, what containment actions were taken, what systems were affected, and how the incident was resolved. This history is the evidence that your IR capability is operational, not aspirational.

Assessors reviewing IR.L2-3.6.2 look for documentation that incidents were tracked and reported to designated officials. The incident log provides that documentation directly. a timestamped record of every incident, every response action, and every reporting event, stored on the appliance where no external access is required to produce it during an assessment.

Incident Response: Live Interface HTML source coming

What You See Inside

  • *Incident record with detection timestamp, severity classification, affected systems, and initial description
  • *Phase-by-phase lifecycle: Detection → Analysis → Containment → Eradication → Recovery → Closure
  • *72-hour reporting clock. calculated from discovery timestamp, visible on all open incidents
  • *DIBNet submission tracking. records submission date, submitting user, and report reference number
  • *Personnel assignment. incident commander and responding personnel named per incident
  • *Evidence attachment. artifacts collected during response linked directly to the incident record
  • *Chain-of-custody log. every action on the incident record is timestamped and attributed to a named user
  • *Closure documentation. root cause, lessons learned, and follow-on POA&M items if applicable
  • *Full incident history exportable for assessor review or post-incident analysis

Incident Lifecycle Phases

Phase What Gets Documented
DetectionDiscovery timestamp, detection method, initial indicators, reporting user
AnalysisScope determination, affected systems, CUI exposure assessment, severity classification
ContainmentContainment actions taken, systems isolated, access revoked, containment timestamp
EradicationRoot cause identification, malware removal, vulnerability patched, eradication confirmation
RecoverySystems restored, validation testing, monitoring period, recovery timestamp
Reporting72-hour clock status, DIBNet submission date, submitting user, report reference
ClosureClosure determination, lessons learned, follow-on POA&M items, closure timestamp

What this replaces

  • *An IR plan that exists as a document but has never been used to handle an actual or simulated incident
  • *Email threads used as de facto incident tracking. no structured record, no timeline, no way to produce a complete incident report on demand
  • *72-hour DFARS reporting deadline managed manually. discovery timestamp not formally recorded, deadline calculated informally, no submission record
  • *No chain of custody on incident artifacts. evidence collected during response not formally linked to the incident record
  • *No incident history to present to assessors. the organization has never had an incident, or if they have, no record exists to demonstrate how it was handled

Practices Satisfied

Practice IDDescription
IR.L2-3.6.1 Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
IR.L2-3.6.2 Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

Related Modules

IR Exercises
Tabletop and simulation exercises use the same incident lifecycle structure. building personnel familiarity with the process before a real incident occurs.
Activity Log
All incident record actions are captured in the Activity Log. the tamper-evident audit trail extends to every update made during an incident response.
Evidence Manager
Artifacts collected during incident response are attached via the Evidence Manager and linked to the IR requirements they satisfy.
POA&M Tracker
Vulnerabilities identified during incident analysis that require remediation are converted directly to POA&M items at incident closure.
See Incident Response in action.

Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.

Request a demo