| Security Incident ABE UML Documentation |
Summary:AttributesCommentsProperties | Detail:Attributes |
Attributes | ||
EntityIdentification | ![]() | |
SecurityEvent | ![]() | |
SecurityIncidentAssessment | ![]() | |
SecurityIncidentAttachment | ![]() | |
SecurityIncidentAttackMethod | ![]() | |
SecurityIncidentHistory | ![]() | |
SecurityThreatActor | ![]() | |
SecurityIncidentRelatedParty | ![]() | |
TroubleTicket | ![]() | |
String | ![]() |
Method used for detection (e.g. user report, detected by sensor, network flow analysis) |
String | ![]() |
If the incident is part of an exercise, this attribute describes that exercise. |
DateTime | ![]() |
Date/time initial detection of activity occurred associated with this incident. |
DateTime | ![]() | |
Boolean | ![]() |
Indicates whether this incident is real or part of an exercise (i.e. part of a test of an organization's security posture). |
Boolean | ![]() |
Boolean for the evaluation whether this incident is a false positive or not. |
DateTime | ![]() | |
String | ![]() |
Free-text analyst description of the current status of the incident |
String | ![]() | |
String | ![]() |
Description of the how the compromised resource was used by the attacker. |
«baseType» TimePeriod | ![]() |
Assessment of start and end date/time event activity associated with this incident occurred. |
Properties:
Alias | |
Classifier Behavior | |
Is Abstract | false |
Is Active | false |
Is Leaf | false |
Keywords | |
Name | SecurityIncident |
Name Expression | |
Namespace | Security Incident ABE |
Owned Template Signature | |
Owner | Security Incident ABE |
Owning Template Parameter | |
Package | Security Incident ABE |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident |
Representation | |
Stereotype | |
Template Parameter | |
Visibility | Public |
Attribute Details |
Public EntityIdentification _entityIdentification
Aggregation | None |
Alias | |
Association | SecurityIncidentRecognizedUsing |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _entityIdentification |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_entityIdentification |
Stereotype | |
Template Parameter | |
Type | EntityIdentification |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public SecurityEvent _securityEvent
Aggregation | None |
Alias | |
Association | SecurityEventIsPartOf |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityEvent |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityEvent |
Stereotype | |
Template Parameter | |
Type | SecurityEvent |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public SecurityIncidentAssessment _securityIncidentAssessment
Aggregation | None |
Alias | |
Association | SecurityIncidentAssessedBy |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | _securityIncidentAssessment |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAssessment |
Stereotype | |
Template Parameter | |
Type | SecurityIncidentAssessment |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public SecurityIncidentAttachment _securityIncidentAttachment
Aggregation | None |
Alias | |
Association | SecurityIncidentSupplementedBy |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityIncidentAttachment |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAttachment |
Stereotype | |
Template Parameter | |
Type | SecurityIncidentAttachment |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public SecurityIncidentAttackMethod _securityIncidentAttackMethod
Aggregation | None |
Alias | |
Association | SecurityIncidentAttackedUsing |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityIncidentAttackMethod |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAttackMethod |
Stereotype | |
Template Parameter | |
Type | SecurityIncidentAttackMethod |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public SecurityIncidentHistory _securityIncidentHistory
Aggregation | None |
Alias | |
Association | SecurityIncidentDocumentedBy |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityIncidentHistory |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentHistory |
Stereotype | |
Template Parameter | |
Type | SecurityIncidentHistory |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public SecurityThreatActor _securityThreatActor
Aggregation | None |
Alias | |
Association | SecurityThreatActorInvolvedIn |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityThreatActor |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityThreatActor |
Stereotype | |
Template Parameter | |
Type | SecurityThreatActor |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public SecurityIncidentRelatedParty _securityTrackingParty
Aggregation | None |
Alias | |
Association | SecurityIncidentTrackedBy |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityTrackingParty |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityTrackingParty |
Stereotype | |
Template Parameter | |
Type | SecurityIncidentRelatedParty |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public TroubleTicket _troubleTicket
Aggregation | None |
Alias | |
Association | SecurityIncidentReferences |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _troubleTicket |
Name Expression | |
Namespace | SecurityIncident |
Opposite | _securityIncident |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_troubleTicket |
Stereotype | |
Template Parameter | |
Type | TroubleTicket |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public String detectionMethod
Method used for detection (e.g. user report, detected by sensor, network flow analysis)
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | detectionMethod |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::detectionMethod |
Stereotype | required |
Template Parameter | |
Type | String |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public String exerciseDescription
If the incident is part of an exercise, this attribute describes that exercise.
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | exerciseDescription |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::exerciseDescription |
Stereotype | |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public DateTime initialDetectionDateTime
Date/time initial detection of activity occurred associated with this incident.
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | initialDetectionDateTime |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::initialDetectionDateTime |
Stereotype | required |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public DateTime intiallyReportedDateTime
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | intiallyReportedDateTime |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::intiallyReportedDateTime |
Stereotype | required |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public Boolean isExercise
Indicates whether this incident is real or part of an exercise (i.e. part of a test of an organization's security posture).
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | isExercise |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::isExercise |
Stereotype | |
Template Parameter | |
Type | Boolean |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public Boolean isFalsePositive
Boolean for the evaluation whether this incident is a false positive or not.
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 1 |
Lower Value | |
Multiplicity | None (1) |
Name | isFalsePositive |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::isFalsePositive |
Stereotype | |
Template Parameter | |
Type | Boolean |
Upper | 1 |
Upper Value | |
Visibility | Public |
Public DateTime lastUpdateDateTime
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | lastUpdateDateTime |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::lastUpdateDateTime |
Stereotype | |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public String status
Free-text analyst description of the current status of the incident
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | status |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::status |
Stereotype | required |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public String synopsis
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | synopsis |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::synopsis |
Stereotype | |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Public String targetUsedAs
Description of the how the compromised resource was used by the attacker.
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | targetUsedAs |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::targetUsedAs |
Stereotype | |
Template Parameter | |
Type | String |
Upper | * |
Upper Value | (*) |
Visibility | Public |
Public «baseType» TimePeriod validFor
Assessment of start and end date/time event activity associated with this incident occurred.
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityIncident |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | validFor |
Name Expression | |
Namespace | SecurityIncident |
Opposite | |
Owner | SecurityIncident |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::validFor |
Stereotype | |
Template Parameter | |
Type | «baseType» TimePeriod |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
Comments |
| Security Incident ABE UML Documentation |
Summary:AttributesCommentsProperties | Detail:Attributes |