| CPC G06F 21/554 (2013.01) [G06F 21/568 (2013.01); G06F 21/57 (2013.01)] | 20 Claims |

|
1. A method, comprising:
creating an incident in response to a cyber event;
identifying one or more authorities, wherein at least some of the one or more authorities are associated with respective authority conditions, at least some of the respective authority conditions are associated with respective attributes, and wherein satisfaction of the respective authority conditions of an authority identifies the authority;
associating at least some of the respective attributes with the incident as incident attributes;
receiving, from a user, first incident attribute values for at least some of the incident attributes;
identifying tasks responsive to at least one of the incident attribute values satisfying respective task conditions of the identified tasks; and
associating the tasks with the incident.
|