Skip to content
Support processInternal ITISO 27001Cross-industryIncident handling
PROCESS TEMPLATE

IT incident handling

From the reported incident through assessment and resolution to feedback for the reporter.

8 steps3 lanes2 decision points3 systemsMaturity managedBPMN 2.0
Excerpt of the process diagram. The remaining steps appear after unlocking. ' + ' SERVICE DESK SPECIALIST TEAM HEAD OF IT Record and classify the report Resolve at first contact Pass to the specialist team 5 more steps

Tell the AI what runs differently at your company and get the adapted process back in seconds. The download gives you BPMN 2.0 XML, ready to import into any BPMS.

METRICS

How to tell whether the process works

Share of incidents resolved at first contact, target 55 percent.

After unlocking
THE PROCESS

8 steps, 3 lanes

1
Record and classify the report

Service desk

2
Resolve at first contact

Service desk

3
Pass to the specialist team

Service desk

Continue with your business address

The full diagram, the process record and the files are reserved for business addresses.

  • The complete diagram
  • All 8 steps in full
  • Goal, scope and trigger
  • Inputs and outputs per step
  • Every metric with its target
  • Risks, opportunities and business rules
  • Standards and legal basis
  • The BPMN file, ready to import

We use the address solely to protect the download. Any address lets you open and adapt the template in Procevia.

CONTEXT

When this template fits

Who it is for

For IT teams between two and twenty people who currently take incidents through a shared mailbox or by word of mouth. Past that size word of mouth stops working, because nobody can say what is still open and how long it has been sitting there.

Where it typically stalls

At the assessment step. If every report is equally urgent, the loudest gets worked first rather than the most important. The template therefore makes assessment its own step, before anyone starts fixing anything.

What it connects to

Upstream is user administration, since a sizeable share of incidents are missing or wrong permissions. Downstream is change control, as soon as the fix means touching the system.

Relation to standards

ISO 27001 requires a controlled way of handling security incidents, meaning capture, assessment, response and documentation. The template maps the general incident path, from which the security incident branches off as a special case.

THE BIGGER PICTURE

Part of these process maps

A single process says little about where it sits in the company. These maps show it among its neighbours.

COMMON QUESTIONS

What people ask first

Is this an ITIL incident process?

It follows the same logic but avoids ITIL vocabulary. Teams using ITIL can rename the steps without changing the structure.

Does it cover security incidents?

Not fully. It shows where the security incident branches off, since that path has its own reporting lines and deadlines.

May I hand the template out in training sessions?

Yes. All templates are published under CC BY 4.0, so you may print, share and teach with them as long as you credit Procevia as the source.

CATEGORISED AS