Severity Matrix
Definition
A two-dimensional scoring tool that combines technical impact and business impact to assign a severity level to a confirmed incident. Outputs are typically a four-level scale: critical, high, medium, and low (or equivalent numerals). The matrix makes prioritisation consistent and defensible across different analysts.
- Dimensions scored
- Technical impact and business impact
- Typical output
- Four-level scale: critical, high, medium, low
- Purpose
- Consistent, defensible incident prioritisation
- Context
- SOC triage
Common questions
Why combine two dimensions instead of scoring severity on one axis?+
A technically severe compromise on a low-value system and a minor technical issue on a critical system need different responses; combining both dimensions prevents either factor alone from over- or under-stating true priority.
Does the severity matrix replace analyst judgment?+
No, it structures and documents the judgment call so different analysts reach comparable ratings for similar incidents, rather than removing the need for the analyst to assess impact.
Related terms
- Alert Fatigue
- The condition in which analysts receive more alerts than they can meaningfully review, leading to delayed responses, dismissed true positives, and reduced...
- Asset Criticality
- A pre-assigned score or label that records how important a system, service, or data set is to the organisation. Used during triage...
- Escalation Threshold
- A defined criterion, based on severity level, asset type, or indicator type, that triggers handoff of an alert from a first-tier analyst...
- False Positive
- A test result that indicates the presence of a target analyte when it is absent. In forensic serology this may mean incorrectly...
- Triage
- The structured process of evaluating an alert to determine whether it is a genuine security incident and, if so, what severity level...