Minimum incident record
Reporter and discovery route; timestamps; systems and organisations in scope; data categories; confirmed facts; decisions; containment and recovery; communications; legal assessment; corrective actions and owners.
Incident response procedure
This operational draft defines the response stages for suspected security, privacy or availability incidents. Contacts, decision authority, severity criteria and contractual notification terms must be completed before production use.
Record the time, source, affected service and known symptoms. Preserve relevant records. Security contact: To be completed before execution.
Assign an incident lead, classify suspected confidentiality, integrity, availability and worker-safety impact, and restrict information to those who need it.
Limit affected access, credentials, functions or integrations while preserving evidence. Avoid actions that increase risk to a reporter.
Establish what happened, what data and organisations may be affected, the likely period, access path and confidence level. Separate confirmed facts from hypotheses.
Consider worker-identification or retaliation risk, customer operational impact, data-subject impact and applicable contractual or legal duties.
Remove the cause where possible, restore service in a controlled way, validate access and monitor for recurrence.
Notify affected customer contacts based on the executed agreement and applicable law. Timing and regulator/data-subject duties remain subject to legal assessment; this draft promises no fixed hour count.
Keep an incident record, decisions, evidence, communications and corrective actions. Complete a post-incident review and track agreed improvements.
Reporter and discovery route; timestamps; systems and organisations in scope; data categories; confirmed facts; decisions; containment and recovery; communications; legal assessment; corrective actions and owners.
Security contact, customer escalation contacts, severity matrix, response roles, approved communication channel, notification window and jurisdiction-specific obligations. No 24/7 monitoring or response service is claimed.