| 663f9932ee7c785b… | A Medium incident is defined as presenting moderate risk with limited impact or requiring additional exploit conditions so that incidents with constrained effect remain in an intermediate severity category. | active | contextual | yes | |
| 63eff9b4b633c9a8… | A High incident causes harm to one or more business units, causes delays to a business unit’s activities, or clearly violates organizational security policy without substantively impacting the business so that it is classified below Critical severity. | active | contextual | yes | |
| acdfae0d6d8768de… | For GDPR purposes, an incident is also classified as Critical when it affects a large number of data subjects so that broad impact on individuals elevates the incident to the highest severity. | active | contextual | yes | |
| 5427ad414c43f9eb… | For GDPR purposes, an incident is also classified as Critical when it could result in significant harm to data subjects so that serious potential impact on individuals triggers the highest severity level. | active | contextual | yes | |
| c932d92cb4adde13… | For GDPR purposes, an incident is also classified as Critical when it involves special categories of personal data so that heightened data sensitivity triggers the highest severity level. | active | contextual | yes | |
| e04a7d18b7d451bd… | A Critical incident is one that is potentially catastrophic to the organization or disrupts day-to-day operations, with likely violation of legal, regulatory, or contractual requirements, so that it receives the highest severity classification. | active | contextual | yes | |
| 71e663804cd65705… | If an incident is confirmed, the CTO must assess organizational impact and assign a severity level so that the required level of remediation effort can be determined. | active | contextual | yes | |
| 3da1d2990fd29216… | The CTO and CISO must conduct a preliminary investigation and risk assessment to review and confirm incident details when an incident may affect customers so that the organization validates the situation before further action. | active | contextual | yes | |
| bd234e8949291d66… | A customer agreement’s specified notification timeframe governs customer notification timing when such an agreement exists so that contractual commitments override general timing expectations. | active | contextual | yes | |
| 211eaa287db3733a… | Affected customers must be notified when an incident is confirmed or reasonably suspected to affect customer data or customer-facing services so that PYRANA.ai complies with applicable legal, regulatory, and contractual obligations. | active | contextual | yes | |
| 60f61d31a4f193cf… | Incident notifications must include the affected systems so that responders know which assets may require containment or remediation. | active | contextual | yes | |
| 68fa718b43f39d53… | Incident notifications must include known evidence of the incident so that responders can evaluate available proof during investigation. | active | contextual | yes | |
| d2dd4613befa76b6… | Incident notifications must include how the incident was discovered so that investigators understand the detection method. | active | contextual | yes | |
| ce545068c4e617eb… | Incident notifications must include the person who discovered the incident so that investigators know the initial discoverer. | active | contextual | yes | |
| dd8229526953e7f2… | Incident notifications must include the date, time, and location of the incident so that responders can establish when and where the event occurred. | active | contextual | yes | |
| c0e3d029b093bf17… | Incident notifications must include a description of the incident so that responders understand what occurred. | active | contextual | yes | |
| e5f0f9a309b97cbe… | Users must report an identified or detected information security incident through the reporting channels described above so that the organization can initiate formal incident handling. | active | contextual | yes | |
| 546c427715f15122… | Low vulnerabilities assessed by PYRANA.ai must be remediated within 90 days so that lower-risk issues are still resolved within a defined maximum period. | active | contextual | yes | |
| 53ff387daae717a8… | Medium vulnerabilities assessed by PYRANA.ai must be remediated within 30 to 60 days so that moderate-risk issues are corrected within the policy’s defined schedule. | active | contextual | yes | |
| 2e359a65c33943c6… | High vulnerabilities assessed by PYRANA.ai must be remediated within 7 to 14 days so that serious but noncritical issues are resolved within the required policy window. | active | contextual | yes | |
| ce66018203ae5980… | Critical vulnerabilities assessed by PYRANA.ai must be remediated within 24 to 72 hours so that the highest-risk issues are addressed on an accelerated timeline. | active | contextual | yes | |
| 39b6f54e9748999b… | Vulnerability tickets are assigned to system, application, or platform owners for further investigation or remediation after assessment so that responsible owners can address the identified issue. | active | contextual | yes | |
| 1801cfcbfe6b7f40… | PYRANA.ai may assign a vulnerability severity level that differs from automated scanners or external researchers when internal knowledge of technical architecture and real-world impact or exploitability supports a different assessment so that remediation reflects PYRANA.ai’s own informed judgment. | active | contextual | yes | |
| e97b67ebace97eba… | Incident notifications should include the affected systems so that responders know which systems may require triage or containment. | active | contextual | yes | |
| d69b7596c4e403be… | Incident notifications should include known evidence of the incident so that available proof is captured during reporting. | active | contextual | yes | |
| 2ea67436abdf203f… | Incident notifications should identify the person who discovered the incident so that responders know the original discoverer. | active | contextual | yes | |
| 38ed362cf7ac64fe… | Incident notifications should include the date, time, and location of the incident to support investigation and response. | active | contextual | yes | |
| a1c892c65c8b03b0… | When an information security incident is identified or detected, users must report it using the reporting channels described above as the first response step. | active | contextual | yes | |
| f9e3d1480c818b19… | Service tickets for vulnerabilities must be assigned to the relevant system, application, or platform owners for further investigation or remediation. | active | contextual | yes | |
| 6ad6fc6893c8d267… | PYRANA.ai may assign a vulnerability severity level that differs from scanner-generated or externally reported severity based on its internal knowledge of technical architecture and real-world impact or exploitability. | active | contextual | yes | |
| 3177ee9ae01df95e… | The engineering department must evaluate the severity of vulnerabilities, and when a vulnerability is determined to be critical or high risk, a service ticket must be created. | active | contextual | yes | |
| 418934047ed24a50… | For each security incident, communication must also be conducted with senior management to evaluate root causes, remediation steps, and lessons learned so that similar incidents can be prevented in the future. | active | contextual | yes | |
| 238030c3f3df3966… | The incident response procedure must be tested at least once per year to verify readiness. | active | contextual | yes | |
| d203f21706f26e51… | The organization must review incident response procedures at least once per year for currency and update them as required so that incident planning and preparation remain appropriate. | active | contextual | yes | |
| 0f1c6ae1f23e13cf… | All information security incidents must be handled through the defined incident management procedures, which require incidents to be tracked, documented, and resolved completely, accurately, and in a timely manner. | active | contextual | yes | |
| c78efe1c5a6d8282… | Information and artifacts associated with security incidents, including files, logs, and screen captures, must be preserved when they may be needed as evidence of a crime. | active | contextual | yes | |
| e46ef5867d105062… | Users must be trained on incident and vulnerability reporting procedures and on their responsibility to report such events so that reporting obligations are understood. | active | contextual | yes | |
| 30bde7970f7d1b07… | Incident reports must be submitted promptly and must include enough detail to support timely triage and response. | active | contextual | yes | |
| dc17637eb1521cdc… | If the primary reporting channel is unavailable, the reporter must escalate the issue in order to the CTO, then the CISO, COO, and CEO so that the incident is still communicated through an alternate path. | active | contextual | yes | |
| d115b21927c697bb… | The designated incident reporting channels include security@pyrana.ai and the company ticketing system for submitting vulnerability and incident reports. | active | contextual | yes | |
| 9bcf49ae68750291… | All users must report any system vulnerability, security incident, or event indicating a possible incident as soon as it is discovered through the company’s designated reporting channels so that timely incident handling can begin. | active | contextual | yes | |
| f6c50a9ae30ebb13… | An information security incident is any suspected, attempted, successful, or imminent threat involving unauthorized access, use, disclosure, breach, modification, or destruction of information, interference with IT operations, or a significant security policy violation. | active | contextual | yes | |
| 0b68c42cda2abd24… | Incident notifications should include the affected systems so that responders can identify the impacted assets that require triage and remediation. | active | contextual | yes | |
| 2f00efd54a7f420f… | Incident notifications should include any known evidence of the incident so that responders can begin assessment using available proof or indicators. | active | contextual | yes | |
| 351640ef95307391… | Incident notifications should include how the incident was discovered so that responders understand the detection method and context. | active | contextual | yes | |
| c607ba881fd387ba… | Incident notifications should include the identity of the person who discovered the incident so that responders know the initial source of discovery. | active | contextual | yes | |
| 40ce74c4b9085ad9… | Incident notifications should include the date, time, and location of the incident so that responders can establish when and where it occurred. | active | contextual | yes | |
| 6f0743f7cf0c22d8… | Incident notifications should include a description of the incident so that responders understand what occurred. | active | contextual | yes | |
| af8209372e62d877… | Vulnerabilities assessed by PYRANA.ai as critical must be remediated within 24 to 72 hours so that the highest-risk weaknesses are addressed urgently. | active | contextual | yes | |
| 4f7de62e467de79a… | Service tickets for assessed vulnerabilities must be assigned to the relevant system, application, or platform owners for further investigation or remediation. | active | contextual | yes | |