Triaging metrics - AWS Security Incident Response User Guide

Triaging metrics

  • Findings received

    • Unit: Count

    • Description: The number of findings sent to triaging.

  • Findings archived

    • Unit: Count

    • Description: The number of findings archived after processed without manual investigation.

  • Findings Manually investigated

    • Unit: Count

    • Description: The number of findings with manual investigation performed.

  • Investigations archived

    • Unit: Count

    • Description: The number of manual investigations resulting in false positive and sent for archiving

  • Investigations escalated

    • Unit: Count

    • Description: The number of manual investigations resulting in a security incident