事件响应
事件处理只需几小时,而非开会讨论:定性、遏制、在 72 小时内通知并告知。每个步骤都会在登记簿中记录时间戳。
回复流程
T+0
Qualifier
Log the incident here: nature, scope, number of people affected. The detection timestamp starts the 72-hour countdown.
T+2 h
Confiner
Revoke exposed API keys, suspend compromised accounts, isolate the affected module. In Sanctuary mode, encrypted files remain unreadable without the local key.
T+24 h
Assess the risk
Determine if the incident poses a risk to the rights and freedoms of individuals. Document the decision, even when it concludes that no notification is required.
T+72 h
Notify the authority
Notify the competent supervisory authority in your jurisdiction. Switching to "Notified" status timestamps this step in the register.
Après
Informer & corriger
Inform the individuals concerned if the risk is high, publish corrective measures, and close the incident with the action plan.
