| 5958aebe934a8e65… | For GDPR purposes, an incident must also be classified as Critical when it involves special categories of personal data so that heightened data protection risk is recognized. | active | contextual | yes | |
| efbbf7aeab853fcb… | A Critical incident is defined as one that is potentially catastrophic to the organization, disrupts day-to-day operations, or is likely to violate legal, regulatory, or contractual requirements. | active | contextual | yes | |
| 5763ed63eb856e3c… | The CTO and CISO must conduct a preliminary investigation and risk assessment to review and confirm incident details before further response decisions are made. | active | contextual | yes | |
| a47ce867a90dae1f… | A customer agreement’s specified notification timeframe governs incident notification timing when such an agreement exists so that contractual obligations take precedence for customer notice. | active | contextual | yes | |
| fc054e1f26fd332f… | Affected customers must be notified when an incident is confirmed or reasonably suspected to affect customer data or customer-facing services so that PYRANA.ai complies with legal, regulatory, and contractual obligations. | active | contextual | yes | |
| faa8819f38abbd13… | Incident notifications must include the affected systems so that responders can identify the scope of impacted technology assets. | active | contextual | yes | |
| 7d30f57a9f1e473d… | Incident notifications must include known evidence of the incident so that responders can begin investigation using the currently available proof. | active | contextual | yes | |
| 648a86c8960ee4cb… | Incident notifications must include how the incident was discovered so that investigators can understand the detection method and initial circumstances. | active | contextual | yes | |
| 580d085d16b44f0c… | Incident notifications must include the person who discovered the incident so that investigators can identify the initial reporter and gather additional context. | active | contextual | yes | |
| e19cc5e1baacc8a4… | Incident notifications must include a description of the incident so that responders understand what occurred at the outset of the investigation. | active | contextual | yes | |
| e68716fb87d234f1… | Users must report an identified or detected information security incident through the reporting channels described above so that the incident response process is formally initiated. | active | contextual | yes | |
| 2190365a45dd6504… | PYRANA.ai requires Low vulnerabilities to be remediated within 90 days after severity determination so that lower-risk issues are still tracked to closure. | active | contextual | yes | |
| 97c6f02a615c9fc3… | PYRANA.ai requires Medium vulnerabilities to be remediated within 30 to 60 days after severity determination so that moderate-risk issues are addressed within a controlled timeframe. | active | contextual | yes | |
| 97bfb8b183a648be… | PYRANA.ai requires High vulnerabilities to be remediated within 7 to 14 days after severity determination so that serious issues are resolved within a defined response window. | active | contextual | yes | |
| e8f6372256d1a058… | PYRANA.ai requires Critical vulnerabilities to be remediated within 24 to 72 hours after severity determination so that the highest-risk issues are addressed urgently. | active | contextual | yes | |
| 8fcf6754a7a731a6… | PYRANA.ai may assign a vulnerability severity level that differs from automated scanners or external researchers when internal technical architecture knowledge and real-world exploitability indicate a different assessment so that remediation reflects PYRANA.ai’s own risk understanding. | active | contextual | yes | |
| eb15602b6db843f6… | All technical steps taken during an incident must be documented in the organization’s incident log so that the response record is complete and reviewable. | active | contextual | yes | |
| 53e4d706d2f7b331… | The CTO must take all necessary steps to resolve the incident in a timely manner and recover information systems, data, and connectivity so that normal operations can be restored promptly. | active | contextual | yes | |
| 077bda5906bec998… | Senior management must be engaged for each security incident to evaluate root causes, remediation steps, and lessons learned so that similar incidents can be prevented in the future. | active | contextual | yes | |
| 2f0e465ab62dc129… | All critical security incidents, including data breaches, must be logged and tracked in the ticketing system and communicated to affected parties so that severe incidents are formally managed and disclosed. | active | contextual | yes | |
| 6e1ad1efd1bd045e… | Preserved incident information must be provided to law enforcement when the incident is determined to be malicious so that external authorities receive relevant evidence for malicious cases. | active | contextual | yes | |
| e434424449e6dff0… | The CTO, in consultation with management sponsors, must determine appropriate incident response activities to contain and resolve incidents so that response actions are selected by accountable leadership. | active | contextual | yes | |
| 28d437b773944f3d… | A Low incident is defined as one presenting minimal risk or a best-practice issue with little security impact so that minor issues are categorized at the lowest severity level. | active | contextual | yes | |
| be945664ade9abde… | A Medium incident is defined as one with moderate risk, limited impact, or additional exploit conditions required so that incidents needing some conditions or having constrained effects are categorized below High severity. | active | contextual | yes | |
| b2a475df064e31c8… | A High incident is defined as one that causes harm to one or more business units, causes delays to a business unit’s activities, or clearly violates organizational security policy without substantively impacting the business so that serious but non-catastrophic incidents are distinguished from Critical ones. | active | contextual | yes | |
| 7491255288710f9a… | For GDPR purposes, an incident must also be classified as Critical when it affects a large number of data subjects so that broad privacy impact triggers the highest incident severity. | active | contextual | yes | |
| c7b8a2b9e509e9b8… | For GDPR purposes, an incident must also be classified as Critical when it could result in significant harm to data subjects so that high-impact privacy risks are escalated appropriately. | active | contextual | yes | |
| aee8029cbf5b5a33… | For GDPR purposes, an incident must also be classified as Critical when it involves special categories of personal data so that sensitive personal-data incidents receive the highest severity treatment. | active | contextual | yes | |
| 394fbfd0f2b79c36… | A Critical incident is defined as one that is potentially catastrophic to the organization or disrupts day-to-day operations, with likely violation of legal, regulatory, or contractual requirements, so that the highest severity is reserved for extreme organizational risk. | active | contextual | yes | |
| aeff47c5514cbd81… | The CTO and CISO must conduct a preliminary investigation and risk assessment to review and confirm incident details so that the organization can validate the situation before further response actions. | active | contextual | yes | |
| c094960eb152db6b… | A customer agreement’s specified notification timeframe governs incident notification timing when such an agreement exists so that contractual commitments control the response deadline. | active | contextual | yes | |
| 403458fe64dd4987… | Incident notifications must include known evidence of the incident so that responders can begin investigation with available supporting facts. | active | contextual | yes | |
| 4b103e694261d8eb… | Incident notifications must include how the incident was discovered so that investigators understand the detection method and context. | active | contextual | yes | |
| c089a2dcaa80c673… | Incident notifications must include the person who discovered the incident so that investigators can identify the initial reporter or witness. | active | contextual | yes | |
| 97dcf355340a5d2e… | Users must report identified or detected information security incidents through the reporting channels described above so that incidents enter the formal response process. | active | contextual | yes | |
| 93e2df4c3b09fdfd… | Low-severity vulnerabilities assessed by PYRANA.ai must be remediated within 90 days so that low-risk issues are still resolved under a defined deadline. | active | contextual | yes | |
| b31122d4d3622511… | Medium-severity vulnerabilities assessed by PYRANA.ai must be remediated within 30 to 60 days so that moderate-risk issues are corrected within the required timeframe. | active | contextual | yes | |
| 65ff522b70901c91… | High-severity vulnerabilities assessed by PYRANA.ai must be remediated within 7 to 14 days so that serious issues are resolved within the defined policy window. | active | contextual | yes | |
| 0d553bfa9a318d41… | Critical vulnerabilities assessed by PYRANA.ai must be remediated within 24 to 72 hours so that the most severe issues are addressed with highest urgency. | active | contextual | yes | |
| 242fd9f57d7f298e… | Vulnerability tickets must be assigned to the relevant system, application, or platform owners for further investigation or remediation so that responsible owners can address identified issues. | active | contextual | yes | |
| 6a994bca62616557… | PYRANA.ai may assign a vulnerability severity level that differs from automated scanners or external researchers when internal technical architecture knowledge and real-world impact or exploitability justify a different assessment so that remediation reflects PYRANA.ai’s own risk understanding. | active | contextual | yes | |
| 847113182c01c86a… | All technical steps taken during an incident must be documented in the organization’s incident log so that the response record is preserved for accountability and review. | active | contextual | yes | |
| 678dc513d99d37cd… | The CTO must take all necessary steps to resolve the incident in a timely manner and recover information systems, data, and connectivity so that normal operations can be restored. | active | contextual | yes | |
| ad6d4cdb1bfc3fa9… | Senior management is communicated with for each security incident to evaluate root causes, remediation steps, and lessons learned so that similar incidents can be prevented in the future. | active | contextual | yes | |
| ceaa73d561df966a… | All critical security incidents, including data breaches, are logged and tracked in the ticketing system and communicated to affected parties so that critical events are formally managed and disclosed. | active | contextual | yes | |
| 89a70239753a7b17… | If an incident is deemed High or Medium, the CTO must work with the CISO and COO to create and execute a communications plan so that users, the public, and other affected parties are informed. | active | contextual | yes | |
| 7a31ed977d0bba99… | Preserved incident information must be provided to law enforcement when the incident is determined to be malicious so that external authorities receive relevant evidence. | active | contextual | yes | |
| a1520adf6f1a7192… | The CTO must take all necessary steps to preserve forensic evidence such as log information, files, and images for further investigation so that the organization can determine whether malicious activity has taken place. | active | contextual | yes | |
| f77116f7c91a68cc… | The CTO, in consultation with management sponsors, must determine appropriate incident response activities to contain and resolve incidents so that response actions are selected with management input. | active | contextual | yes | |
| 28e877316f06cd99… | A Low incident is defined as minimal risk or a best-practice issue with little security impact so that minor issues are categorized at the lowest severity level. | active | contextual | yes | |