Hello everyone my question is, what a newly established Security Operations Center (SOC) team would use when opening a ticket in Jira based on a received alarm for below examples:
Login failure
Hardware dish issue
Suspicious login attempt
User account with admin rights locked out
User is logged in from outside the country
This would be in Jira service management tool would you pick this activity as an incident or as a problem