Documenting and tracking the work carried out on a case is crucial. It allows for information sharing and collaboration across the SOC team, and enables SOC leaders to export case information to share with stakeholders. Case management provides two ways to accomplish this: the Notes tab and the History tab.
The ability to add notes enables analysts to document and track their work. Case notes use Markdown so you can create structured and easily readable notes. This includes the ability to apply bold text, create lists, and highlight important content. If a case has to be reassigned or escalated, notes enable other team members to quickly understand what action has been taken on a case.
Case management automatically adds a record of each interaction with the case on the History tab. This provides an audit log of all actions and activity taken by the analysts working on the case. Case history shows the date, time, user, and activity that was carried out. To ensure there is an accurate record of the work done, you cannot edit or delete this information.