# What is Alert Triage?

> Alert triage is the initial, structured assessment of a security alert to decide what it may represent, how urgently it needs attention, and what should happen next.

- Canonical URL: https://yellowcube.eu/glossary/alert-triage/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The analyst or automated workflow adds context, checks the evidence, groups duplicates, estimates affected scope and business impact, and assigns a reasoned disposition or escalation path.

Triage should be fast enough to protect response time without pretending to be a complete investigation. Severity describes the potential consequence of an event, while priority also depends on confidence, exposure, asset or identity criticality, active exploitation, and time sensitivity. A high-severity alert may be low priority after validation, and a subtle alert affecting a critical administrator may require immediate action.

### Key points

- **Context to add:** Alert logic, triggering evidence, identity and asset details, related events, known changes, exposure, control status, and previous cases.
- **Possible outcomes:** Escalate for investigation or response, contain under an approved playbook, merge with a related case, monitor, or close with documented reasoning.
- **Quality measures:** Time to acknowledge, consistency of decisions, reopened cases, missed incidents, escalation quality, and feedback into detection engineering.
- **Important limitation:** Automation can enrich and prioritize alerts, but silent closure based on fragile rules can suppress real incidents. High-risk dispositions need traceability and review.

### Related terms

[Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Security orchestration, automation and response (SOAR)](<https://yellowcube.eu/glossary/security-orchestration-automation-and-response/>) · [False positive](<https://yellowcube.eu/glossary/false-positive/>) · [False negative](<https://yellowcube.eu/glossary/false-negative/>)

### Sources

[NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [NIST Cybersecurity Framework 2.0](https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

