Templates
Information Security Incident Register Template
Log and track security incidents from detection and triage through escalation to lessons learned — supporting ISO 27001 controls A.5.24–A.5.28 and PDP Law breach notification duties.
- Format
- XLSX
- Size
- 17 KB
- Language
- Indonesian & English
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
In short
An incident register is the central record of every information security incident with its timeline, severity classification, impact, response actions, and lessons learned. ISO 27001 controls A.5.24 to A.5.28 require planned incident management, and the register is both its evidence and the raw material for post-incident review.
What This Document Is For
The greatest pressure during an incident is not the technical decision but the deadline. Indonesia's PDP Law allows 3×24 hours to notify a failure of personal data protection, and the clock starts when the incident becomes known — not when the response finishes. An organisation without a ready recording format spends part of that window deciding what to record.
This template supplies the format in advance. Its columns follow the order events demand: detection, classification, containment, recovery, then review. The personal data notification flag stands separately so that decision does not get buried among technical notes.
What's Inside
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Controls A.5.24–A.5.26 | Planning, assessment, and response to information security incidents. |
| ISO/IEC 27001:2022 | Controls A.5.27 & A.5.28 | Learning from incidents and collection of evidence. |
| Law 27/2022 (PDP Law) | Breach notification | The 3×24 hour notification duty and the trail evidencing it. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Does every disruption need recording as an incident?
No. What gets recorded is an event that affects, or could affect, the confidentiality, integrity, or availability of information. Purely operational outages belong in ordinary IT incident management. But when in doubt, record it — a slightly over-complete register beats one that missed a real incident.
When does the 3×24 hour clock start?
When the organisation becomes aware of the personal data protection failure, not when the investigation concludes or systems recover. That is why the detection time column here sits separately from time of occurrence — the gap between them is often the first question asked during scrutiny.
Who decides the severity level?
The role named in your incident response procedure, against written criteria. Classification that rests on a responder's on-the-spot judgement produces a register whose trends cannot be analysed, because similar incidents get rated differently over time.
Need guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.