Incident Closure Template
Migrated from the repository documentation set.
Incident Metadata
- Incident id:
- Title:
- Severity: Sev 1 | Sev 2 | Sev 3
- Start time (UTC):
- End time (UTC):
- Owner approver:
- Primary responder:
Summary
- What happened:
- Customer or service impact:
- Detection source:
Containment and Recovery
- Immediate containment actions:
- Recovery actions:
- Revalidation actions:
Root Cause and Confidence
- Root cause hypothesis:
- Confidence level: high | medium | low
- Evidence references:
Control State at Closure
- Security controls restored.
- Access policy revalidated.
- Monitoring and alerting status verified.
- Provider communication archived if required.
Residual Risk and Follow-up
- Residual risks:
- Required next-steps items:
- Target completion dates:
Sign-off
- Owner close decision:
- Close timestamp (UTC):