10.1 Purpose
This policy outlines Keepr's procedures for detecting, responding to, and recovering from security incidents and data breaches.
10.2 Incident Classification
| Severity | Description | Response Time |
|---|---|---|
| Critical | Data breach, system compromise | Immediate (< 1 hour) |
| High | Unauthorised access attempt, malware | 4 hours |
| Medium | Security misconfiguration, suspicious activity | 24 hours |
| Low | Minor security event, informational | 72 hours |
10.3 Incident Response Procedure
- Detection & Reporting: automated monitoring, user reports, third-party notifications, audits.
- Initial Response: confirm validity, assess severity and scope, activate the response team, document.
- Investigation: collect evidence and logs, analyse root cause, determine affected data/users.
- Containment: isolate affected systems, stop the attack, prevent further damage, preserve evidence.
- Eradication: remove attacker access, patch vulnerabilities, restore to a clean state, verify.
- Recovery: restore from backups, bring systems online, monitor for re-infection.
- Notification: notify affected users within 72 hours and authorities where required.
- Post-Incident Review: document lessons learned, update procedures, implement preventive measures.
10.4 Communication Plan
Internal communication covers response-team activation, status updates, executive briefings, and debriefs. External communication covers user notification within 72 hours, authority notification where required, and transparent, factual information.
10.5 Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Incident Commander | Overall coordination and decision-making |
| Security Lead | Investigation and technical response |
| Communications Lead | Internal and external communication |
| Legal Lead | Regulatory compliance and notification |
| Operations Lead | System restoration and recovery |