
Security Incident Investigation & Response Documentation
Investigate security incidents and generate compliant reports for airport operations
What You Can Do
Rapidly analyze security incidents with structured threat assessment and automatic report generation. The skill evaluates incident severity, documents evidence properly, and produces investigation reports compliant with airport security standards and regulatory requirements. You get actionable threat classifications, timeline reconstructions, and remediation recommendations ready for stakeholder review and escalation.
Features
Automatically categorize incidents using standard airport security taxonomy and determine severity levels (Low, Medium, High, Critical) with documented justification.
Assess potential risks to airport operations, passenger safety, and infrastructure using structured threat modeling and scenario analysis.
Generate investigation reports that meet TSA, ICAO, and regional regulatory requirements with all mandatory sections and documentation.
Build detailed chronological sequences of incident events from witness statements, security footage logs, and operational records.
Organize and evaluate witness accounts, flag inconsistencies, and integrate credible information into the incident narrative.
Create structured evidence checklists and chain-of-custody documentation for physical or digital artifacts related to the incident.
Generate specific, actionable recommendations to prevent similar incidents, prioritized by impact and feasibility.
Example Output
Incident Report Summary
Incident ID: SEC-2026-0847 Classification: Unauthorized Access Attempt Threat Level: Medium Date/Time: August 10, 2026, 14:35 UTC Location: Terminal 3, Security Checkpoint B
Timeline
- 14:32 Individual attempts to enter secure area with invalid badge
- 14:34 Security officer detains subject for questioning
- 14:35 Airport police notified and respond
- 14:45 Subject identified as contract worker with expired credentials
Threat Assessment No direct threat to operations or passengers. Procedural security control functioned as designed. Risk of credential fraud exists if ID verification processes not reinforced.
Recommendations
- Implement daily credential verification audits (Impact: High, Timeline: 1 week)
- Upgrade badging system to real-time revocation checks (Impact: Critical, Timeline: 30 days)
- Enhanced training for checkpoint officers on credential validation (Impact: Medium, Timeline: 1 week)
What's Included
- Incident Intake Template: Structured form to capture all essential incident details, participants, timeline, and environmental context.
- Threat Assessment Framework: Validated methodology for evaluating incident severity, risk factors, and escalation criteria aligned with airport security standards.
- Compliant Report Template: Professional investigation report format meeting TSA, ICAO, and regional compliance requirements with required sections and fields.
- Timeline Builder: Tool to reconstruct incident chronology from multiple sources and identify critical decision points.
- Evidence Checklist: Comprehensive documentation guide for physical evidence, digital artifacts, witness statements, and chain-of-custody procedures.
- Recommendation Framework: Structured approach to generating preventive measures, prioritized by risk reduction impact and implementation feasibility.
Who It's For
- Airport Security Directors
- Incident Response Managers
- Security Operations Center Coordinators
- Compliance and Audit Officers
- Terminal Operations Managers
Best For
- Documenting active security incidents
- Threat level assessment and classification
- Investigation report generation
- Post-incident compliance verification
- Cross-departmental incident briefings







