Skip to content

Incidents and concerns

How something gets reported, what happens automatically at High severity and above, and why every incident review opens a corrective action.

Audience: ISMS Admin.

The two routes in: an administrator logs an incident directly, or a member of staff reports a concern from your SharePoint site and Certaria brings it into the register. Both end in the same place.

Your people use the Report a concern route on your ISMS site. They add their own entry and can see only their own, which is the point: someone reporting a concern about a colleague should not find it readable by that colleague.

Certaria syncs concerns into the incident register on a schedule. A concern is a report, not yet a finding, and triage is yours.

What happens automatically at High severity

Section titled “What happens automatically at High severity”

Below High severity, nothing is sent. That is deliberate: an alert that fires for everything is an alert nobody reads.

The review stage opens a corrective action

Section titled “The review stage opens a corrective action”

When an incident reaches its Review stage, Certaria opens a corrective action against it automatically, so the lesson is captured rather than lost when the incident is closed.

Three things worth knowing:

  • It checks first whether one already exists, so moving back and forth through the stages will not create duplicates.
  • The new item appears under Corrective Actions.
  • It records the action quietly and sends no notification, because you are already looking at the incident when it happens.

Closing an incident without a corrective action is the failure mode this prevents. ISO 27001 asks what you learned, not just what happened.

Corrective actions are chased like anything else

Section titled “Corrective actions are chased like anything else”

Once open, a corrective action has an owner and a due date, and it is picked up by the same reminders as compliance tasks: a daily message to its owner when overdue, and a warning as the due date approaches. See Tasks and deadlines.

  • Can you show the report reached the right person? The System Health record of alerts.
  • What did you change as a result? The corrective action, and whether it closed.
  • How does someone raise a concern? The route on your site, and that it is available to everyone.
  • Have you had none at all? An empty incident register is not automatically good news, and an auditor may read it as nobody knowing how to report. The daily prompt is part of the answer.
SymptomCauseFix
A serious incident sent no alertIt was saved below High severitySeverity drives the alert. Reclassify and save
Concerns are not appearing in the registerThe sync is scheduled, not instant, or the site URL in configuration is wrongWait for the next run, then check the configuration record
Duplicate corrective actions on one incidentShould not happen: the check prevents itIf it did, close the surplus and report it
An incident closed with nothing learnedIt never reached the Review stage, so no corrective action openedMove it through Review rather than straight to Closed
Staff say they cannot find where to reportThe site navigation was not provisioned, or they are looking in the appConcerns are reported on the SharePoint site, not in the model-driven app