01 ·
Scope
One endpoint or many?
This single answer tells me whether I'm looking at a local condition or a systemic failure. The remediation is completely different.
02 ·
Impact
Broken, degraded, or at risk?
I classify by availability, integrity, confidentiality — not by how loud the ticket is. Loud is not the same as critical.
03 ·
Time Behavior
When does it happen?
Constant, intermittent, after reboot, after patch, after policy sync. When it happens is often as valuable as what happens.
04 ·
Reproducibility
Can I trigger it safely?
If I can reproduce it, I can test it. If I can't, I need to catch it live — and that changes my whole collection strategy.
05 ·
Blast Radius
What's adjacent?
What can become collateral? I need to know what I'm not allowed to break before I start moving anything.
06 ·
Constraints
What can't I touch?
What must stay online? What's compliance-sensitive? Knowing the hard edges tells me exactly where I'm allowed to work.