Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE
Class SecurityIncident

Attributes
EntityIdentification _entityIdentification _entityIdentification
SecurityEvent _securityEvent _securityEvent
SecurityIncidentAssessment _securityIncidentAssessment _securityIncidentAssessment
SecurityIncidentAttachment _securityIncidentAttachment _securityIncidentAttachment
SecurityIncidentAttackMethod _securityIncidentAttackMethod _securityIncidentAttackMethod
SecurityIncidentHistory _securityIncidentHistory _securityIncidentHistory
SecurityThreatActor _securityThreatActor _securityThreatActor
SecurityIncidentRelatedParty _securityTrackingParty _securityTrackingParty
TroubleTicket _troubleTicket _troubleTicket
String detectionMethod detectionMethod

Method used for detection (e.g. user report, detected by sensor, network flow analysis)

String exerciseDescription exerciseDescription

If the incident is part of an exercise, this attribute describes that exercise.

DateTime initialDetectionDateTime initialDetectionDateTime

Date/time initial detection of activity occurred associated with this incident.

DateTime intiallyReportedDateTime intiallyReportedDateTime

Date and time initially reported.

Boolean isExercise isExercise

Indicates whether this incident is real or part of an exercise (i.e. part of a test of an organization's security posture).

Boolean isFalsePositive isFalsePositive

Boolean for the evaluation whether this incident is a false positive or not.

DateTime lastUpdateDateTime lastUpdateDateTime

Last date/time the incident was updated.

String status status

Free-text analyst description of the current status of the incident

String synopsis synopsis

Free text synopsis for analyst notes

String targetUsedAs targetUsedAs

Description of the how the compromised resource was used by the attacker.

«baseType» TimePeriod validFor validFor

Assessment of start and end date/time event activity associated with this incident occurred.


Properties:

Alias
Classifier Behavior
Is Abstractfalse
Is Activefalse
Is Leaffalse
Keywords
NameSecurityIncident
Name Expression
NamespaceSecurity Incident ABE
Owned Template Signature
OwnerSecurity Incident ABE
Owning Template Parameter
PackageSecurity Incident ABE
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident
Representation
Stereotype
Template Parameter
VisibilityPublic

Attribute Details

 _entityIdentification
Public EntityIdentification _entityIdentification
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityIncidentRecognizedUsing
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_entityIdentification
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_entityIdentification
Stereotype
Template Parameter
TypeEntityIdentification
Upper*
Upper Value(*)
VisibilityPublic


 _securityEvent
Public SecurityEvent _securityEvent
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityEventIsPartOf
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_securityEvent
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityEvent
Stereotype
Template Parameter
TypeSecurityEvent
Upper*
Upper Value(*)
VisibilityPublic


 _securityIncidentAssessment
Public SecurityIncidentAssessment _securityIncidentAssessment
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityIncidentAssessedBy
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Name_securityIncidentAssessment
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAssessment
Stereotype
Template Parameter
TypeSecurityIncidentAssessment
Upper1
Upper Value(1)
VisibilityPublic


 _securityIncidentAttachment
Public SecurityIncidentAttachment _securityIncidentAttachment
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityIncidentSupplementedBy
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_securityIncidentAttachment
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAttachment
Stereotype
Template Parameter
TypeSecurityIncidentAttachment
Upper*
Upper Value(*)
VisibilityPublic


 _securityIncidentAttackMethod
Public SecurityIncidentAttackMethod _securityIncidentAttackMethod
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityIncidentAttackedUsing
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_securityIncidentAttackMethod
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAttackMethod
Stereotype
Template Parameter
TypeSecurityIncidentAttackMethod
Upper*
Upper Value(*)
VisibilityPublic


 _securityIncidentHistory
Public SecurityIncidentHistory _securityIncidentHistory
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityIncidentDocumentedBy
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_securityIncidentHistory
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentHistory
Stereotype
Template Parameter
TypeSecurityIncidentHistory
Upper*
Upper Value(*)
VisibilityPublic


 _securityThreatActor
Public SecurityThreatActor _securityThreatActor
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityThreatActorInvolvedIn
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_securityThreatActor
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityThreatActor
Stereotype
Template Parameter
TypeSecurityThreatActor
Upper*
Upper Value(*)
VisibilityPublic


 _securityTrackingParty
Public SecurityIncidentRelatedParty _securityTrackingParty
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityIncidentTrackedBy
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_securityTrackingParty
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityTrackingParty
Stereotype
Template Parameter
TypeSecurityIncidentRelatedParty
Upper*
Upper Value(*)
VisibilityPublic


 _troubleTicket
Public TroubleTicket _troubleTicket
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityIncidentReferences
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_troubleTicket
Name Expression
NamespaceSecurityIncident
Opposite_securityIncident
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_troubleTicket
Stereotype
Template Parameter
TypeTroubleTicket
Upper*
Upper Value(*)
VisibilityPublic


 detectionMethod
Public String detectionMethod

Method used for detection (e.g. user report, detected by sensor, network flow analysis)

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
NamedetectionMethod
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::detectionMethod
Stereotyperequired
Template Parameter
TypeString
Upper*
Upper Value(*)
VisibilityPublic


 exerciseDescription
Public String exerciseDescription

If the incident is part of an exercise, this attribute describes that exercise.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
NameexerciseDescription
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::exerciseDescription
Stereotype
Template Parameter
TypeString
Upper1
Upper Value(1)
VisibilityPublic


 initialDetectionDateTime
Public DateTime initialDetectionDateTime

Date/time initial detection of activity occurred associated with this incident.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
NameinitialDetectionDateTime
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::initialDetectionDateTime
Stereotyperequired
Template Parameter
TypeDateTime
Upper1
Upper Value(1)
VisibilityPublic


 intiallyReportedDateTime
Public DateTime intiallyReportedDateTime

Date and time initially reported.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
NameintiallyReportedDateTime
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::intiallyReportedDateTime
Stereotyperequired
Template Parameter
TypeDateTime
Upper1
Upper Value(1)
VisibilityPublic


 isExercise
Public Boolean isExercise

Indicates whether this incident is real or part of an exercise (i.e. part of a test of an organization's security posture).

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
NameisExercise
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::isExercise
Stereotype
Template Parameter
TypeBoolean
Upper1
Upper Value(1)
VisibilityPublic


 isFalsePositive
Public Boolean isFalsePositive

Boolean for the evaluation whether this incident is a false positive or not.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower1
Lower Value
MultiplicityNone (1)
NameisFalsePositive
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::isFalsePositive
Stereotype
Template Parameter
TypeBoolean
Upper1
Upper Value
VisibilityPublic


 lastUpdateDateTime
Public DateTime lastUpdateDateTime

Last date/time the incident was updated.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
NamelastUpdateDateTime
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::lastUpdateDateTime
Stereotype
Template Parameter
TypeDateTime
Upper1
Upper Value(1)
VisibilityPublic


 status
Public String status

Free-text analyst description of the current status of the incident

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Namestatus
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::status
Stereotyperequired
Template Parameter
TypeString
Upper1
Upper Value(1)
VisibilityPublic


 synopsis
Public String synopsis

Free text synopsis for analyst notes

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Namesynopsis
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::synopsis
Stereotype
Template Parameter
TypeString
Upper1
Upper Value(1)
VisibilityPublic


 targetUsedAs
Public String targetUsedAs

Description of the how the compromised resource was used by the attacker.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
NametargetUsedAs
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::targetUsedAs
Stereotype
Template Parameter
TypeString
Upper*
Upper Value(*)
VisibilityPublic


 validFor
Public «baseType» TimePeriod validFor

Assessment of start and end date/time event activity associated with this incident occurred.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityIncident
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
NamevalidFor
Name Expression
NamespaceSecurityIncident
Opposite
OwnerSecurityIncident
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::validFor
Stereotype
Template Parameter
Type«baseType» TimePeriod
Upper1
Upper Value(1)
VisibilityPublic

Comments