| Security Incident ABE UML Documentation |
| Summary:AttributesCommentsProperties | Detail:Attributes |
| Attributes | ||
| EntityIdentification | ||
| SecurityEvent | ||
| SecurityIncidentAssessment | ||
| SecurityIncidentAttachment | ||
| SecurityIncidentAttackMethod | ||
| SecurityIncidentHistory | ||
| SecurityThreatActor | ||
| SecurityIncidentRelatedParty | ||
| TroubleTicket | ||
| String |
Method used for detection (e.g. user report, detected by sensor, network flow analysis) |
|
| String |
If the incident is part of an exercise, this attribute describes that exercise. |
|
| DateTime |
Date/time initial detection of activity occurred associated with this incident. |
|
| DateTime | ||
| Boolean |
Indicates whether this incident is real or part of an exercise (i.e. part of a test of an organization's security posture). |
|
| Boolean |
Boolean for the evaluation whether this incident is a false positive or not. |
|
| DateTime | ||
| String |
Free-text analyst description of the current status of the incident |
|
| String | ||
| String |
Description of the how the compromised resource was used by the attacker. |
|
| «baseType» TimePeriod |
Assessment of start and end date/time event activity associated with this incident occurred. |
|
Properties:
| Alias | |
| Classifier Behavior | |
| Is Abstract | false |
| Is Active | false |
| Is Leaf | false |
| Keywords | |
| Name | SecurityIncident |
| Name Expression | |
| Namespace | Security Incident ABE |
| Owned Template Signature | |
| Owner | Security Incident ABE |
| Owning Template Parameter | |
| Package | Security Incident ABE |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident |
| Representation | |
| Stereotype | |
| Template Parameter | |
| Visibility | Public |
| Attribute Details |
Public EntityIdentification _entityIdentification
| Aggregation | None |
| Alias | |
| Association | SecurityIncidentRecognizedUsing |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _entityIdentification |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_entityIdentification |
| Stereotype | |
| Template Parameter | |
| Type | EntityIdentification |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public SecurityEvent _securityEvent
| Aggregation | None |
| Alias | |
| Association | SecurityEventIsPartOf |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _securityEvent |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityEvent |
| Stereotype | |
| Template Parameter | |
| Type | SecurityEvent |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public SecurityIncidentAssessment _securityIncidentAssessment
| Aggregation | None |
| Alias | |
| Association | SecurityIncidentAssessedBy |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | _securityIncidentAssessment |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAssessment |
| Stereotype | |
| Template Parameter | |
| Type | SecurityIncidentAssessment |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public SecurityIncidentAttachment _securityIncidentAttachment
| Aggregation | None |
| Alias | |
| Association | SecurityIncidentSupplementedBy |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _securityIncidentAttachment |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAttachment |
| Stereotype | |
| Template Parameter | |
| Type | SecurityIncidentAttachment |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public SecurityIncidentAttackMethod _securityIncidentAttackMethod
| Aggregation | None |
| Alias | |
| Association | SecurityIncidentAttackedUsing |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _securityIncidentAttackMethod |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentAttackMethod |
| Stereotype | |
| Template Parameter | |
| Type | SecurityIncidentAttackMethod |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public SecurityIncidentHistory _securityIncidentHistory
| Aggregation | None |
| Alias | |
| Association | SecurityIncidentDocumentedBy |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _securityIncidentHistory |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityIncidentHistory |
| Stereotype | |
| Template Parameter | |
| Type | SecurityIncidentHistory |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public SecurityThreatActor _securityThreatActor
| Aggregation | None |
| Alias | |
| Association | SecurityThreatActorInvolvedIn |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _securityThreatActor |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityThreatActor |
| Stereotype | |
| Template Parameter | |
| Type | SecurityThreatActor |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public SecurityIncidentRelatedParty _securityTrackingParty
| Aggregation | None |
| Alias | |
| Association | SecurityIncidentTrackedBy |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _securityTrackingParty |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_securityTrackingParty |
| Stereotype | |
| Template Parameter | |
| Type | SecurityIncidentRelatedParty |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public TroubleTicket _troubleTicket
| Aggregation | None |
| Alias | |
| Association | SecurityIncidentReferences |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | _troubleTicket |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | _securityIncident |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::_troubleTicket |
| Stereotype | |
| Template Parameter | |
| Type | TroubleTicket |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public String detectionMethod
Method used for detection (e.g. user report, detected by sensor, network flow analysis)
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | detectionMethod |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::detectionMethod |
| Stereotype | required |
| Template Parameter | |
| Type | String |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public String exerciseDescription
If the incident is part of an exercise, this attribute describes that exercise.
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | exerciseDescription |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::exerciseDescription |
| Stereotype | |
| Template Parameter | |
| Type | String |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public DateTime initialDetectionDateTime
Date/time initial detection of activity occurred associated with this incident.
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | initialDetectionDateTime |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::initialDetectionDateTime |
| Stereotype | required |
| Template Parameter | |
| Type | DateTime |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public DateTime intiallyReportedDateTime
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | intiallyReportedDateTime |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::intiallyReportedDateTime |
| Stereotype | required |
| Template Parameter | |
| Type | DateTime |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public Boolean isExercise
Indicates whether this incident is real or part of an exercise (i.e. part of a test of an organization's security posture).
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | isExercise |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::isExercise |
| Stereotype | |
| Template Parameter | |
| Type | Boolean |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public Boolean isFalsePositive
Boolean for the evaluation whether this incident is a false positive or not.
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 1 |
| Lower Value | |
| Multiplicity | None (1) |
| Name | isFalsePositive |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::isFalsePositive |
| Stereotype | |
| Template Parameter | |
| Type | Boolean |
| Upper | 1 |
| Upper Value | |
| Visibility | Public |
Public DateTime lastUpdateDateTime
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | lastUpdateDateTime |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::lastUpdateDateTime |
| Stereotype | |
| Template Parameter | |
| Type | DateTime |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public String status
Free-text analyst description of the current status of the incident
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | status |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::status |
| Stereotype | required |
| Template Parameter | |
| Type | String |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public String synopsis
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | synopsis |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::synopsis |
| Stereotype | |
| Template Parameter | |
| Type | String |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
Public String targetUsedAs
Description of the how the compromised resource was used by the attacker.
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | * |
| Name | targetUsedAs |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::targetUsedAs |
| Stereotype | |
| Template Parameter | |
| Type | String |
| Upper | * |
| Upper Value | (*) |
| Visibility | Public |
Public «baseType» TimePeriod validFor
Assessment of start and end date/time event activity associated with this incident occurred.
| Aggregation | None |
| Alias | |
| Association | |
| Association End | |
| Class | SecurityIncident |
| Datatype | |
| Default | |
| Default Value | |
| Is Composite | false |
| Is Derived | false |
| Is Derived Union | false |
| Is Leaf | false |
| Is Ordered | false |
| Is Read Only | false |
| Is Static | false |
| Is Unique | true |
| Keywords | |
| Lower | 0 |
| Lower Value | (0) |
| Multiplicity | 0..1 |
| Name | validFor |
| Name Expression | |
| Namespace | SecurityIncident |
| Opposite | |
| Owner | SecurityIncident |
| Owning Association | |
| Owning Template Parameter | |
| Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Incident ABE::SecurityIncident::validFor |
| Stereotype | |
| Template Parameter | |
| Type | «baseType» TimePeriod |
| Upper | 1 |
| Upper Value | (1) |
| Visibility | Public |
| Comments |
| Security Incident ABE UML Documentation |
| Summary:AttributesCommentsProperties | Detail:Attributes |