This section captures the affected employee's identity, the compromised asset's technical specifications, and precise geospatial-temporal metadata surrounding the theft incident. Accuracy is critical for forensic analysis and insurance claims.
Employee Full Legal Name
Employee Unique Identifier
Employee Department/Division
Employee Job Role Title
Employee Primary Contact Number
Employee Alternative Contact Number
Employee Corporate Email Address
Employee Personal Email Address (for recovery coordination)
Employee Work Arrangement at Time of Incident
Fully Remote (Home Office)
Hybrid (Corporate & Remote)
Traveling (Business Trip)
Customer Site Visit
Co-working Space
Public Location (Cafe/Airport)
Provide detailed travel itinerary: cities, hotels, transportation modes
Customer/Client Organization Name
Co-working Space Name and Address
Describe public location context: venue name, address, time spent
Device Asset Specification & Identification Matrix
Compromised Asset Inventory
Device Category | Manufacturer | Model Name/Number | Serial Number (Primary ID) | Corporate Asset Tag (Barcode) | MAC Address (Wi-Fi) | MAC Address (Ethernet/Bluetooth) | IMEI (for cellular devices) | Device Issue Date to Employee | Operating System & Version | ||
|---|---|---|---|---|---|---|---|---|---|---|---|
A | B | C | D | E | F | G | H | I | J | ||
1 | Laptop | Dell Inc. | Latitude 7420 | SN-8X4T9P2 | AST-2023-8472 | A4:CF:12:8B:3D:E1 | N/A | N/A | 5/15/2023 | Windows 11 Enterprise 22H2 | |
2 | |||||||||||
3 | |||||||||||
4 | |||||||||||
5 | |||||||||||
6 | |||||||||||
7 | |||||||||||
8 | |||||||||||
9 | |||||||||||
10 |
Exact Date and Time Theft Discovered (Employee Local Time)
Employee Time Zone at Discovery
Last Confirmed Physical Possession (Date/Time)
Theft Location Physical Address or GPS Coordinates
Is the theft location the employee's designated remote work address?
Detailed Description of Location Environment
Was the device connected to corporate VPN at time of theft or last known session?
Last Known VPN IP Address
Explain network connectivity status and last known corporate network access
Was the device domain-joined or Azure AD joined?
Domain Name or Azure AD Tenant ID
This section documents official law enforcement engagement and reconstructs the circumstances of loss to support investigation, insurance claims, and potential recovery efforts.
Has a formal police report been filed with local law enforcement?
Police Report/Crime Reference Number
Explain why police report was not filed and planned next steps
Law Enforcement Agency Name
Precinct/Station Address
Investigating Officer Name and Badge Number
Officer Contact Information (Email/Phone)
Date and Time Police Report Filed
Upload Official Police Report Document (PDF/Scan)
Upload Photo of Police Report Receipt or Acknowledgment
Theft Incident Classification
Burglary (Unlawful Entry)
Robbery (Use of Force/Threat)
Larceny/Theft (No Contact)
Pickpocketing/Subtle Theft
Vehicle Break-in
Lost/Missing (Unconfirmed Theft)
Other
Was the vehicle corporate-owned or personal?
Describe the 'Other' classification in detail
Estimated Date and Time of Theft (if different from discovery)
Employee Activity at Time of Incident (select all applicable)
Working on device
Device in bag/backpack
Device left unattended in vehicle
Device left in hotel room
Device in checked luggage
Device in carry-on luggage
Device visible on table/seat
Device secured in lockbox/safe
Walking/commuting
Socializing/dining
Were there any witnesses to the theft or suspicious activity?
Witness Details: Name, Contact, Statement Summary
Was CCTV or surveillance footage available at the location?
CCTV Details: Camera locations, retention period, contact for footage retrieval
Was the device stored in a locked container (safe, lockbox, trunk) when stolen?
Describe container type and locking mechanism
Explain why device was not secured in locked container
Assess the physical security of the theft location environment
Very Poor (No security measures)
Poor (Minimal/basic security)
Average (Standard locks/lighting)
Good (Controlled access/CCTV)
Excellent (24/7 security/monitoring)
Detailed Narrative of Events Leading to Loss
Was any other corporate or personal property stolen simultaneously?
This section verifies execution of remote data destruction commands and comprehensive revocation of all digital access credentials to prevent unauthorized network or data access.
Has a remote wipe command been initiated via Mobile Device Management (MDM)?
MDM Remote Wipe Status
Command Pending (Device Offline)
Command Sent (Awaiting Acknowledgment)
Wipe Successfully Executed (Confirmed)
Wipe Failed/Error Returned
Command Initiation Timestamp
Command Sent Timestamp
Wipe Confirmation Timestamp
Error Details and Failure Reason
Explain why MDM wipe was not initiated and alternative mitigation steps
Was the device enrolled in Microsoft Intune, Jamf Pro, or other MDM platform?
MDM Platform Name and Version
Was the device configured with 'Find My Device' (Apple) or 'Find My Device' (Android/Windows)?
Provide tracking status and last known location if available
Access Token and Credential Revocation Matrix
Digital Access Revocation Checklist
Revocation Action Completed | Access Type | Revocation Timestamp | Performed By (Initials) | Notes/Confirmation Details | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | Corporate VPN Access | 1/15/2024, 2:30 PM | JS | Disabled in FortiGate, session killed | ||
2 | Corporate Email Account | 1/15/2024, 2:32 PM | JS | All tokens revoked | ||
3 | Single Sign-On (SSO) Sessions | 1/15/2024, 2:35 PM | JS | Okta sessions terminated globally | ||
4 | Cloud Storage Sync (OneDrive/Box) | |||||
5 | Source Code Repository Access | |||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Have all active directory sessions been terminated across all domain controllers?
Were any privileged/administrative credentials cached or stored on the device?
List all privileged accounts and immediate containment actions taken
Was a remote lock command sent to prevent device boot or access?
Lock Command Reference ID
Has the device been flagged in asset management system as 'Stolen - Security Incident'?
Has the SIM card (if applicable) been deactivated with mobile carrier?
Carrier Name and Deactivation Reference
Additional Digital Containment Measures Implemented
This section conducts a rigorous audit of data sensitivity levels stored on or accessible from the compromised device to quantify breach severity and determine regulatory notification obligations.
Official Corporate Data Classification Level of Device
Public (Non-sensitive)
Internal Use (Minor sensitivity)
Confidential (Moderate sensitivity)
Restricted (High sensitivity)
Top Secret (Critical sensitivity)
Describe specific confidential data categories present
Describe specific restricted data categories present
Describe specific top secret data categories present
Was the device protected with Full Disk Encryption (FDE) at time of theft?
Encryption Standard and Algorithm
AES-256 (BitLocker/FileVault)
AES-128
Other FIPS 140-2 Validated
Unknown/Proprietary
Software-based (e.g., VeraCrypt)
Justification for lack of encryption and immediate risk mitigation
Was the device powered on or in sleep/hibernation mode when stolen?
Was the user logged in and session unlocked?
Describe session state and potential data exposure risk
Select all categories of sensitive data potentially stored on or accessible via the device
Customer Personal Identifiable Information (PII)
Employee PII or HR Records
Financial Data (Corporate or Customer)
Unpublished Financial Results
Strategic Plans or M&A Documents
Source Code or Intellectual Property
Encryption Keys or Certificates
Privileged Credentials
Health/Medical Records (HIPAA)
Legal/Attorney-Client Communications
Third-Party Confidential Data
No sensitive data present
Did the device have offline/local copies of cloud-synced files?
Which cloud storage services had offline copies?
Microsoft OneDrive
Google Drive
Box
Dropbox Business
iCloud Drive
Corporate File Share (Synced)
Other
Were any cached credentials stored on the device?
Was the device configured with auto-save or recent documents cache?
Describe applications with auto-save and potential data remnants
Last Successful Cloud Backup or Sync Timestamp
Was any data actively being transferred or synced at time of theft?
Describe data transfer context and potential interception risk
Data Exposure Risk Assessment Matrix
Rate the potential exposure severity for each data category (1=Minimal, 5=Catastrophic)
Customer PII Exposure | |
Employee PII Exposure | |
Financial Data Exposure | |
Intellectual Property Theft | |
Credential Compromise Risk | |
Regulatory Non-Compliance Risk |
Does this incident potentially trigger regulatory breach notification requirements?
Select potentially applicable regulatory frameworks
GDPR (EU Data Protection)
CCPA/CPRA (California Privacy)
HIPAA (Health Data)
PCI DSS (Payment Card)
SOX (Financial Reporting)
Industry-Specific Regulation
Cross-Border Data Transfer Rules
Estimated Volume of Sensitive Records Potentially Compromised
Has a preliminary data inventory been conducted from backup logs?
Upload Data Inventory Analysis Report
This final section requires dual-authority verification from Information Security and IT Service Management leadership to confirm all required containment, documentation, and escalation actions have been satisfactorily completed before incident closure.
Information Security Officer (ISO) Verification Checklist
ISO Security Controls Validation
Control Verified | Security Control Item | Verification Method | Verified By (Name/Role) | Verification Timestamp | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | Remote wipe command issued and confirmed | MDM console log review | InfoSec Team | 1/15/2024, 3:45 PM | ||
2 | All access tokens revoked globally | Identity platform audit | InfoSec Team | 1/15/2024, 4:00 PM | ||
3 | Data sensitivity assessment completed | Review of Sections 1-4 | InfoSec Team | 1/15/2024, 4:30 PM | ||
4 | Regulatory breach evaluation conducted | |||||
5 | Forensic image obtained (if applicable) | |||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Does the ISO recommend escalation to executive leadership or legal counsel?
Escalation Rationale and Recommended Actions
IT Service Desk Lead Operational Closure Validation
IT Service Desk Operational Verification
Task Completed | Operational Task | Completion Evidence | Completed By (Initials) | Completion Timestamp | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | Employee issued temporary replacement device | Asset tag RT-2024-001 | TK | 1/16/2024, 9:00 AM | ||
2 | User account security hardening completed | MFA re-enrollment | TK | 1/16/2024, 9:15 AM | ||
3 | Incident ticket fully documented | Ticket #INC-2024-0847 updated | TK | 1/16/2024, 10:00 AM | ||
4 | Insurance claim initiated | |||||
5 | Asset management system updated | |||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Has the employee been provided with security awareness retraining?
Training Module Completed and Date
Schedule and plan for mandatory security retraining
Has a replacement device been provisioned to the employee?
Replacement Device Asset Tag
Explain delay and estimated provisioning timeline
Information Security Officer Digital Signature
Information Security Officer Name (Printed)
Information Security Officer Title
Information Security Officer Sign-off Timestamp
IT Service Desk Lead Digital Signature
IT Service Desk Lead Name (Printed)
IT Service Desk Lead Title
IT Service Desk Lead Sign-off Timestamp
Do both authorizing officers approve incident closure?
Final Incident Summary and Lessons Learned Recommendations
Should this incident be included in quarterly security metrics and board reporting?
To configure an element, select it on the form.