Incident Management
Incident Management handles disruptions, failures, and security events affecting IT and OT infrastructure. In OT environments, incidents may affect production processes or safety systems — rapid response and full traceability are critical.
Incident lifecycle
Section titled “Incident lifecycle”New → Acknowledged → Investigating → Mitigation in Progress → Resolved → ClosedOptional states: Escalated, Waiting for Vendor, Waiting for Maintenance Window
Severity levels
Section titled “Severity levels”| Severity | Description | Example |
|---|---|---|
| Critical | Production stopped or safety risk | PLC unresponsive on production line |
| High | Major degradation, partial impact | SCADA server unreachable |
| Medium | Limited impact, workaround available | Switch port flapping |
| Low | Minor issue, no immediate impact | Failed backup job |
Creating an incident
Section titled “Creating an incident”-
Go to Incidents → New Incident
-
Fill in the required fields:
- Title — short, descriptive
- Severity — Critical / High / Medium / Low
- Category — IT / OT / Security / Network / Safety
- Site — affected location
- Description — full context of the issue
-
Link affected assets — search and attach the relevant PLCs, servers, or network devices. This enables impact analysis and incident history per device.
-
Save. The incident is created with status
Newand SLA timers start.
OT-specific fields
Section titled “OT-specific fields”When the category is OT or Safety, additional fields become available:
- Production impact — is production affected?
- Safety impact — is there a safety risk?
- Operational criticality — criticality of the affected system
Linking to other records
Section titled “Linking to other records”From an incident you can:
- Create a Change Request — if remediation requires infrastructure changes
- Create a Problem — if this is a recurring pattern
- Link a Vulnerability — if the incident relates to a known CVE
- Reference Knowledge articles — attach runbooks or procedures
Service level agreements help teams meet first-response and resolution targets for incidents.
Configure policies
Section titled “Configure policies”-
Open Settings → SLA Policies.
-
Create or edit a policy. Typical fields:
- Name — e.g.
Critical OT — 15m / 4h - First response (minutes) — time to acknowledge or begin work
- Resolution (minutes) — time to reach Resolved
- Pause on waiting — whether timers pause in states like Waiting for Vendor (when enabled for your tenant)
- Name — e.g.
-
Associate the policy with severity, category, or site rules as your tenant UI allows.
-
Save. New and updated incidents matching the policy start SLA clocks automatically.
On the incident record
Section titled “On the incident record”- SLA due times appear on the incident detail page when a policy applies.
- Approaching breach may show visual flags in the UI.
- Responsible users receive notifications when Settings → Notifications includes Incident SLA — see Notification Settings.
Escalation
Section titled “Escalation”When a target is missed or nearly missed, Monozu may notify assignees and managers per your notification configuration. Tune policies and notifications together to avoid noise — see Troubleshooting — Incident SLA.