Template · Security

Security: Templates

Four working templates: the response approval record, the incident timeline, the risk exception and the quarterly access review.

Markdown. No sign-up, no email.

1. Response approval record#

One per response action. Completed before the action runs, not after.

FieldEntry
Event
Risk score[And the sentence explaining it. A score alone is not a case]
Evidence[What was observed, with timestamps]
Proposed response[Specifically: which account, which range, which host]
Blast radius[What else this affects if the finding is wrong. Disabling a service account stops an attacker and may stop payroll]
If we do nothing for an hour[The other half of the decision, and the half usually missing]
Approved by[A named human. Never an agent]
Approved at[Time. Feeds the approval-latency measure]
Executed at
Verified[Confirm it actually took effect. An unverified response is an assumption]

2. Incident timeline#

TimeEventSourceEvidence kept
[What happened, not what was concluded][Where the proof is stored]
FieldEntry
First compromise, best estimate[Not first detection. The gap is dwell time]
Detected at
Detected by[Monitoring / person / third party. "Third party" is its own serious finding]
Contained at
Evidence preserved before containment?[Snapshot, memory, logs. Containment destroys what you need to size the incident]
Lateral movement checked[Assume yes until disproven. The first host found is rarely the first used]
Data involved[If possibly yes, Legal was told at this time: ____]
Credentials rotated after access closed[Rotating first tells the attacker they are seen while they still have a way in]
Root cause
What would have detected it sooner[The output that matters]

3. Risk exception#

FieldEntry
Risk being accepted
Why it cannot be fixed now[Cost, dependency, timing. "Busy" is not a reason]
Compensating control[What reduces it meanwhile, or explicitly none]
Accepted by[A named person with authority to carry it]
Accepted on
Expires[A date. An exception without one is a permanent decision nobody admitted making]
Reviewed monthly

4. Quarterly access review#

AccountTypeOwnerPrivilegesLast usedAction
[Human / service][A name. An unowned service account is the one nobody notices being used][Keep / reduce / remove]

Unused for 90 days means remove, not query. Restoring access takes minutes. Standing unused privilege is permanent attack surface, and every review that ends in "leave it for now" adds to it.

Summary
Accounts reviewed
Removed
Credentials older than 180 days rotated
Service accounts without a named owner[Should be zero]

Using these together#

The charter sets out what security owns, the SOPs say when each is produced, the KPIs define what the approval record feeds, and the workflows name who receives each output. An approval record with a blank blast-radius row should be refused.

Back to Security

Get new material when it is published

Everything here is free and stays free. There is no form in front of any document. If you want to know when new guides and templates go up, leave an email.

Roughly monthly. Unsubscribe in one click. We do not share your address, and we will not call you.