Solutions

Security incident management software

An incident record in SecBoard is the classification, the status, what happened, what was done, and the files. Alert intake from a monitor such as Wazuh is the SOC module, not this registry.

The incident registry

The module stores classification, type, current status, the event description, actions taken, and additional files. Access is limited by company. The record can be sent by email. The knowledge base has a separate article on an incident response plan.

What this is not

SOC/FIM receives alerts by webhook from an external system, for example Wazuh, and tracks status, investigation, escalation, and hash or AI analysis of those alerts. That does not replace the system that produced the alert. GDPR breach records live in the GDPR module.

Questions

No. SOC/FIM receives alerts from an external monitor such as Wazuh. The incident module is the security-incident registry.

Access is company-based. The record can also be emailed.

In the GDPR module, as a data-breach record, separate from the general incident registry.

Yes. The knowledge base has an incident response plan article.

Related