ASUME

Trust Center

Incident Response

How ASUME detects, investigates, contains, and notifies customers of personal-data and security incidents. A named Incident Response Team and tabletop programme are still being formalised.

Incident response process

ASUME detects, investigates, and contains personal-data and security incidents, and notifies Customers when required. The current process is described in Security Measures.

The people who operate the Service handle incidents today. A named, standing Incident Response Team with a published runbook is still being formalized.

Incident reporting and customer notification

If the confidentiality, integrity, or availability of data is compromised, ASUME notifies affected Customers and, where the law requires it, the relevant authority. Customer-notification practices are described in Security Measures.

A standalone incident-reporting playbook with named authority contacts is still being formalized and is not independently verified.

Incident response team

ASUME is formalizing a designated Incident Response Team so that containment and mitigation have a named owner, with other people added when the scope of an incident requires it.

Until that team is documented, incidents are handled by the people who operate the product and infrastructure. A standing IRT is not independently verified.

Post-incident review

After an incident is contained, ASUME reviews what happened so that the root cause can be addressed and the process improved.

A published post-incident report format that is shared with a defined set of stakeholders is still being defined and is not independently verified.

Tabletop exercises

A published tabletop-exercise programme is a roadmap item.

Listing tabletop exercises here is not a representation that a scheduled exercise programme exists today.