Timeline Log
Definition
A chronological, append-only record capturing every analyst action and finding during the response, time-stamped at the moment of entry in UTC. It is the primary source document from which all other reports are derived.
- Structure
- Chronological, append-only record
- Timestamp basis
- Moment of entry, in UTC
- Content
- Every analyst action and finding during the response
- Role
- Primary source document for all other reports
Common questions
Why insist on UTC timestamps rather than local time?+
An incident response often spans systems and personnel in different time zones. A single UTC reference removes ambiguity when reconstructing the exact order of events across log sources, and it avoids errors from daylight-saving transitions during a long-running investigation.
Why is the timeline log kept append-only?+
An append-only record cannot be quietly edited after the fact to smooth over a mistake or reorder events, which preserves its credibility as the authoritative source when the final incident report and any legal proceeding are built from it.
Related terms
- Breach Notification
- The legal obligation to inform regulators and affected individuals when personal data is compromised in a security incident. Timelines and thresholds differ...
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Incident Ticket
- The structured record opened in an IT service management or case management system when an alert is escalated to an incident. It...
- Lessons-Learned Report
- A post-incident review document identifying what succeeded, what failed, the root cause, and specific recommended changes to policy, tooling, or training. Produced...
- Post-Incident Report
- The formal written account produced after an incident is closed. It synthesises the timeline log into a structured narrative covering the incident...