Incident Management & Breach Response (Annex A.5.24)
1. Reporting an Incident
Any staff member discovering a suspected security event (lost laptop, phishing email clicked, unusual account behavior) must immediately report it:
* Emergency Slack / Teams: #incident-response
* Email Hotline: security@yourdomain.com
2. Response Lifecycle
[1. Detection & Triage] ➔ [2. Containment] ➔ [3. Eradication] ➔ [4. Recovery] ➔ [5. Post-Incident Review]
- Detection & Triage: Determine scope, affected systems, and data classification.
- Containment: Isolate affected endpoint from network; revoke active OAuth/M365 session tokens; rotate credentials.
- Eradication: Identify root cause, wipe/reimage machines, patch exploited vulnerabilities.
- Recovery: Restore verified clean data from immutable cloud backups; monitor system behavior.
- Post-Incident Review: Document timeline, lessons learned, and update risk registers within 5 business days.
3. Statutory Breach Notification (UK GDPR / ICO)
If personal data is compromised presenting a risk to individuals' rights and freedoms: * The Data Protection Officer (DPO) and Executive Management must be notified immediately. * Formal notification to the Information Commissioner's Office (ICO) must occur within 72 hours of becoming aware.