| db55e7f95ae2e09f… | The incident log must include status values of open, closed, or archived so that the current lifecycle state of the incident is recorded. | active | contextual | yes | |
| 9f8a58910caccda0… | The incident log must include mitigations applied, such as patching or re-imaging, so that remediation actions are documented for review and follow-up. | active | contextual | yes | |
| eedb76dbbca8a0b4… | The incident log must include evidence so that supporting material for the incident and response is retained in the official record. | active | contextual | yes | |
| 8d851e9b79c8781c… | The incident log must include the root cause, such as a source address, website malware, or vulnerability, so that the origin of the incident is documented. | active | contextual | yes | |
| 8e68dd7034165e17… | The incident log must include the incident severity level so that the seriousness of the event is recorded for response and review purposes. | active | contextual | yes | |
| 2bd0a334cc83f798… | The incident log must include a description of the incident so that the event is clearly identified in the official response record. | active | contextual | yes | |
| 49bced125422bd39… | The CTO must take all necessary steps to resolve incidents promptly and recover information systems, data, and connectivity so that business operations can be restored in a timely manner. | active | contextual | yes | |
| ded57ed2c7e800a6… | Senior management must be informed for each security incident so that root causes, remediation steps, and lessons learned can be evaluated to prevent similar incidents in the future. | active | contextual | yes | |
| 96ce6ee7929251a3… | The document is version 3 so that the current revision of the incident response policy is identified. | active | contextual | yes | |
| b48694f3beff50fa… | The policy document was approved on 04/07/2026 so that its formal approval date is explicitly recorded. | active | contextual | yes | |
| 8944225a86fdd734… | Eric Tarnowski is identified in the document as the Secondary Signatory so that the policy records an authorized secondary approver. | active | contextual | yes | |
| 4389a95493e1786f… | James Canterbury is identified in the document as the Primary Signatory so that the policy records an authorized primary approver. | active | contextual | yes | |
| ab4d9ed05e0bfeac… | Upon receiving a personal device incident report, the CTO or designated responder must deny re-access until the user confirms the replacement or recovered device meets the Personal Device and BYOD Standard. | active | contextual | yes | |
| 8cf04c0a6b1740ed… | Upon receiving a personal device incident report, the CTO or designated responder must remove the work account and company data from managed mobile devices so that organizational information is protected. | active | contextual | yes | |
| d567a44401c2e816… | Upon receiving a personal device incident report, the CTO or designated responder must reset the user's passwords and revoke active sessions so that compromised access is terminated. | active | contextual | yes | |
| 5da98d9aab9c34a9… | Upon receiving a report of a lost, stolen, or suspected-compromised personal device, the CTO or designated responder must block the reported device from company systems so that access is immediately restricted. | active | contextual | yes | |
| 031384a7e4895cfd… | Users must report any lost, stolen, or suspected-compromised personal device used for company work immediately and no later than 24 hours after discovery, following the reporting chain defined in the policy. | active | contextual | yes | |
| de65ac3fadaa8c35… | External authorities that may be contacted as part of incident response include law enforcement agencies, data protection authorities, relevant regulatory bodies, affected customers, and third-party service providers. | active | contextual | yes | |
| 2da77b81952f2a4b… | All low-risk incidents are periodically reviewed to identify trends, ensure documentation accuracy, and determine whether follow-up actions or preventative improvements are needed. | active | contextual | yes | |
| 8be841bed5ef5c7f… | In some low-risk cases, a brief review and notation are sufficient without the need for a formal ticket so that minor incidents can be handled efficiently. | active | contextual | yes | |
| 45afd317d599b00b… | Upon identification of a low-risk incident, the responsible team member records the incident in the designated tracking system and creates a ticket when appropriate so that the event is tracked consistently. | active | contextual | yes | |
| 133cc81cc18d37f1… | Low-risk incidents generally do not require immediate escalation or extensive investigation because they pose minimal impact to operations, security, or compliance. | active | contextual | yes | |
| 6650216bb76aa5d0… | Low-risk severity incidents are handled through streamlined processes focused on documentation and routine review so that minor events receive proportionate treatment. | active | contextual | yes | |
| 5435f58447d6abb0… | Where necessary, the CEO must take disciplinary action when a user's activity is deemed malicious so that malicious behavior is formally addressed. | active | contextual | yes | |
| 57ff85884cd972fb… | The CTO must notify all users of the incident, conduct additional training if necessary, and present lessons learned so that future occurrences can be prevented. | active | contextual | yes | |
| 0b9c854dc0aba8f5… | Depending on incident severity, the CEO may elect to contact external authorities, including law enforcement, private investigation firms, and government organizations, as part of the incident response. | active | contextual | yes | |
| a996b5a9a2ba0850… | After an incident has been resolved, the CTO must conduct a post mortem that includes root cause analysis and documentation of lessons learned so that future response can improve. | active | contextual | yes | |
| 55eee6f4f5baa651… | The incident log must contain disclosures identifying parties to which incident details were disclosed, such as customers, vendors, or law enforcement, so that external communications are recorded. | active | contextual | yes | |
| 8a7ad1fa18fb93d4… | The incident log must contain status values including open, closed, or archived so that the current state of the incident is tracked. | active | contextual | yes | |
| 94ade0864bfaf0c4… | The incident log must contain mitigations applied, such as patching or re-imaging, so that remediation actions are documented. | active | contextual | yes | |
| f21db81d4b458bc9… | The incident log must contain evidence related to the incident so that supporting material for analysis and investigation is retained. | active | contextual | yes | |
| e7a329e0d0a5093c… | The incident log must contain the root cause, such as source address, website malware, or vulnerability, so that the origin of the incident is documented. | active | contextual | yes | |
| 15c24d3a3f3e8852… | The incident log must contain the incident severity level so that the seriousness of the event is explicitly documented. | active | contextual | yes | |
| 212f0bf7d5b14250… | The incident log must contain a description of the incident so that the event being handled is clearly recorded. | active | contextual | yes | |
| 948ea407ed341ecc… | All technical steps taken during an incident must be documented in the organization's incident log so that the response record is complete and reviewable. | active | contextual | yes | |
| f14c860448d08e22… | The CTO must take all necessary steps to resolve incidents in a timely manner and recover information systems, data, and connectivity so that business and technical operations are restored. | active | contextual | yes | |
| be4a211ee74f9dc6… | Senior management must be communicated with for each security incident so that root causes, remediation steps, and lessons learned can be evaluated to prevent similar incidents in the future. | active | contextual | yes | |
| 7e6334824120ac23… | All critical security incidents, including data breaches, must be logged and tracked in the ticketing system and communicated to affected parties so that incident handling and notification are formally managed. | active | contextual | yes | |
| 9259984cb4d42196… | The CTO must work with the CISO and the COO to create and execute a communications plan for High or Medium incidents so that users, the public, and other affected parties are informed. | active | contextual | yes | |
| 7aee352f5085c87f… | Information collected to determine whether malicious activity occurred must be preserved and provided to law enforcement when the incident is determined to be malicious so that potential criminal investigation evidence is retained. | active | contextual | yes | |
| 513dbce2f5f6b6cd… | Communication with senior management must occur for each security incident so that root causes, remediation steps, and lessons learned can be evaluated to prevent similar future incidents. | active | contextual | yes | |
| 0a8ac18f32874104… | All critical security incidents, including data breaches, must be logged and tracked in the ticketing system and communicated to affected parties so that critical events are formally managed and disclosed. | active | contextual | yes | |
| a1d7f8619da912e9… | Preserved incident information must be provided to law enforcement when the incident is determined to be malicious so that external authorities can investigate malicious activity. | active | contextual | yes | |
| 2b3040c360a23dbb… | The CTO must take all necessary steps to preserve forensic evidence such as log information, files, and images for further investigation so that malicious activity can be determined. | active | contextual | yes | |
| db34c24476ce59fe… | The CTO, in consultation with management sponsors, must determine appropriate incident response activities to contain and resolve incidents so that response actions are aligned with management oversight. | active | contextual | yes | |
| af6171da22146d64… | A Low incident is defined as one with minimal risk or a best-practice issue that has little security impact so that minor issues are categorized at the lowest severity. | active | contextual | yes | |
| 6b8e32ab6d6ef2e2… | A Medium incident is defined as one with moderate risk, limited impact, or additional exploit conditions required so that incidents of intermediate severity are distinguished from higher and lower levels. | active | contextual | yes | |
| 67eb5bd14361c0b1… | A High incident is defined as one that harms one or more business units, causes delays to business unit activities, or clearly violates organizational security policy without substantively impacting the business overall. | active | contextual | yes | |
| 298d0cb85b812400… | For GDPR purposes, an incident must also be classified as Critical when it affects a large number of data subjects so that large-scale privacy impact receives the highest severity. | active | contextual | yes | |
| 8b1d667c014211ef… | For GDPR purposes, an incident must also be classified as Critical when it could result in significant harm to data subjects so that serious privacy risk is escalated appropriately. | active | contextual | yes | |