Hello there!

Need Help? We are right here!

miniorange Support~
miniOrange Email Support

Thanks for your Enquiry.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:


Incident Response Plan

Last updated: January 02, 2025

1. Policy Overview

This Security Incident Response Policy (the "Policy") is formulated in alignment with ISO 27001:2013 and is designed to establish comprehensive measures for the detection, management, and resolution of security vulnerabilities and incidents. The primary objective of this Policy is to ensure the prompt identification of security breaches and the effective response to mitigate any potential harm or damage arising from such incidents.

This Policy further outlines the procedures, responsibilities, and guidelines for the implementation of a security incident response framework, which includes the identification, classification, escalation, and resolution of security incidents. Additionally, the Policy defines performance metrics and reporting mechanisms to assess the effectiveness of the security incident response process.

2. Scope

This Policy applies to all individuals who access, use, or interact with information systems managed by miniOrange, including but not limited to employees, contractors, and any external parties who engage with systems or information under the control of miniOrange (hereinafter collectively referred to as "Users"). The provisions of this Policy shall be made accessible to all Users and shall be deemed applicable to all actions involving the use of such information systems.

3. Roles and Responsibilities

The Information Security Officer and the senior management team shall be responsible for the implementation, maintenance, and oversight of this Policy. They have to ensure that all employees, contractors, and relevant stakeholders have been provided access to, and are required to review and acknowledge the terms of, this Policy. Furthermore, the Information Security Officer and senior management shall ensure ongoing compliance with the provisions set forth herein.

4. Policy

The policy is defined to ensure that in any event of disruption of business operations, miniOrange will take appropriate actions for the continuity and minimization of impact. miniOrange will also keep a track of such incidents and take preventive measures to minimize the impact of controllable events in future. The incidents are described based on the severity level from high to low.

  • Highest Severity(Level 1)
    A Service failure or severe degradation due to environmental threat so that no one is able to access any business resources. Such events could be:
    • Natural disaster - Floods, Earthquakes,etc.
    • Terrorist Attack
    • Power Failure, Power Spikes, Fire etc.
  • Medium Severity (Level 2)
    Service failure and not being able to access any business resources, or information security systems depending on third-party suppliers / vendors. Such events could be:
    • Amazon Web Service (AWS) Downtime
    • Google Server Downtime
  • Low Severity (Level 3)
    A service not available due to incidents in the internal network miniOrange. Such events could be:
    • a. Loss of Data
      The unauthorized loss, alteration, or destruction of data, whether intentional or unintentional, shall be considered a violation of this Policy. Such incidents may include, but are not limited to, unauthorized access to, modification of, or destruction of information stored within or transmitted through the organization’s information systems.
      • a.1. Unauthorized Modification/Update to Information Processing Facility
        Any unauthorized access or modification to the Information Processing Facility, which results in a breach of the integrity, confidentiality, or availability of information, shall be considered an access violation and a violation of this Policy. This includes, but is not limited to, unauthorized changes to system configurations, data, or software that compromise the security of the information systems.
      • a.2. External Attack on Infrastructure
      • Any external attack targeting the organization’s infrastructure, including but not limited to phishing, Distributed Denial of Service (DDoS) attacks, viruses, malware, or other malicious activities, shall be deemed a security breach under this Policy. Such incidents shall be addressed immediately to mitigate their impact on the organization’s information systems.
      • a.3. Unexpected Malfunction of Devices
        The unexpected malfunction or failure of devices, caused by factors such as incompatible software installations or updates, shall be considered a security incident when such malfunctions result in a disruption to the proper functioning, integrity, or security of the organization's information systems.
    • b. Impact of Incidents
      • Impact Analysis of the incidents can be done based on the severity of the incident.
      • Impact of Highest Severity Events is described in the Business Continuity Policy Document.
      • Impact of Medium Severity Events could result in the stoppage of business operations completely for miniOrange as well as their customers.
      • Impact of Low Severity Events could result in the stoppage of only some business activities compromising the Information Security.
    • c. Incident Logging

      All the incidents must be logged before executing the incident response plan. Any stakeholder of miniOrange can report the incident to the top management or to the members of ISMS Team.

      Top Management can also be informed of incidents with the notification activities set up for each incident.

      All employees as trained must report any level of incident to the top management/concerned team within 24 hours.

      Customers can also report the incidents to the miniOrange anytime with the concerned issues.

      Incidents must be reported through email, phone call, or support ticket to the concerned team/top management with details of the incident.

      Employees must be trained on the procedures for reporting incidents. Failure to report information security incidents shall be considered to be a security violation and will be reported to the Human Resources (HR) Manager for disciplinary action.

      Information and artifacts associated with security incidents (including but not limited to files, logs, and screen captures) must be preserved in the event that they need to be used as evidence of a crime.

      As soon as the incident is detected the incident is logged by the ISMS Team so other people are aware of the incident. In this case, a document will be prepared and circulated throughout the people. This document will have

      Title Description
      Incident Summary What’s an emergency ?
      Description What is the impact of the incident ? Impact on customers as well.
      Fault A Service that is unavailable or faulty.
      Affected Products Which products will be affected ?

5. Communication Plan

Communication procedure is extremely important as soon as the incident response plan is executed. It can be done via email or through telephone conversation. The email will be circulated to all the necessary parties either by HR/Operations or by the team members depending on the incident. The notification or the email will include the type of incident, impact, measures or actions taken post-incident and current status of the incident. The communications/notifications will continue until the incident is resolved or taken care of.

Communication with Employees: HR/ Operations/Departmental Team of miniOrange will be responsible for informing all the employees of the miniOrange as soon as an incident is recorded and measures taken to tackle it.

This communication will be done preferably with formal email or verbal communication if required.

Communication with customers: Customers will be informed by the departmental team members if required. Communication will be done through the formal email.

Customers will be notified within 8 hrs of the incident or depending on the severity of the incident.

6. Incident Management

The response plan from miniOrange will be based on the severity and the impact of the incident. The Response Plan for Severity Events will be executed in the 4 Phases described below.

Phase 1: Immediate Action
The ISMS Team will assess the situation based on the severity of the Incident as described above. For Highest Severity (Level 1), a Business Continuity Plan will be executed. For Medium Severity (Level 2) Service Plan will be executed and Low Severity (Level 3) Generic Plan will be implemented.

Phase 2: Testing and Monitoring
Following the classification of the incident, the response team shall monitor and document all actions taken post-incident in accordance with the determined incident level. The response team is also responsible for ensuring that all relevant stakeholders, including key personnel, are promptly notified of the incident and the corrective or preventive measures implemented. Such monitoring and communication shall be carried out in compliance with the organization's incident response protocols and applicable legal and regulatory requirements.

Phase 3: Backup Execution and Post-Incident Meeting
Once all the initial communication has been made to all the departments and the employees, the response team needs to assess the situation and develop the follow-up action plan.
The Follow-Up Action Plan shall include an evaluation of the anticipated duration of the incident, determining whether the situation is expected to persist for one hour, one day, one week, or longer. Based on this assessment, tailored strategies shall be developed to ensure the continuity of business operations. These strategies will address the needs of various departments, services, and third parties, aiming to mitigate operational disruption and minimize financial loss to the organization. The strategies shall be implemented in a manner consistent with the organization’s operational priorities and legal obligations.

Phase 4: Ongoing Assessment of the Incident
The Incident Response Team shall convene, either in person or through online means, to continuously assess the evolving nature and timescale of the incident. The team shall ensure that all relevant parties are kept informed and that all critical business functions are addressed in accordance with established priorities. Senior management shall hold regular meetings to reassess the situation, oversee the execution of the incident response plan, and maintain communication with key stakeholders, including staff, employees, senior management, and third parties, until the incident is resolved or adequately mitigated in accordance with organizational and legal requirements.

7. Service Plan

miniOrange’s information processing operations are reliant on cloud infrastructure provided by Amazon Web Services (AWS). The organization utilizes the full suite of AWS infrastructure for the hosting of applications and the management of databases. To ensure uninterrupted operations, AWS automatically maintains backup services in a separate Availability Zone. In accordance with the Backup Policy, services can be promptly reinitiated from an alternate AWS zone in the event of a disruption.

All miniOrange employees and clients are duly informed of the organization's reliance on AWS services. Any incident occurring within the AWS environment will be addressed in accordance with the incident response procedures outlined in AWS’s Service Level Agreement (SLA) https://aws.amazon.com/compute/sla/ which can be accessed at AWS SLA. Affected parties will be kept informed of the incident status based on updates from AWS.

In addition, miniOrange utilizes Google Workspace for internal communication, personal data storage, and as a communication channel. Any disruption in Google’s services could impact both internal and external communications. In the event of such an incident, miniOrange will utilize telephonic communication channels as a contingency measure to maintain business continuity.

Google’s services are provided under the terms of their SLA, which can be reviewed at Google Workspace SLA https://workspace.google.com/terms/sla.html. All employees will be promptly informed about the status of any incident based on the information provided by Google.

8. Generic Plan

Any incidents at AWS can impact miniOrange operations as well as all business activities. miniOrange has assigned the role of Incident Manager with all the responsibilities and authority for the incident. The Incident Manager is empowered to take any action necessary to resolve the incident, which includes paging anyone in the organization and keeping those involved in an incident focused on restoring the service.

9. Responsibilities of Incident Manager

The Incident Manager is responsible for ensuring effective communication regarding the incident, both internally within the organization and externally to relevant stakeholders. Alternatively, the Incident Manager may delegate this responsibility to an appropriate individual. It is essential that all impacted parties, both internal and external, are promptly informed of the nature and impact of the incident and the organization's ongoing efforts to resolve the matter.

The Incident Manager shall assemble a response team by selecting members from various departments, as necessary, and assigning them specific roles in the restoration of services. The Incident Manager will ensure that the team is promptly engaged in mitigating the incident and restoring normal operations.

The Incident Manager will work closely with the response team to resolve the incident and restore services to normal functionality. During this process, the Response Team will provide regular updates on the status of the incident to ensure transparency and ongoing communication with affected stakeholders.

Upon resolution of the incident, the Incident Manager, in collaboration with the response team, shall oversee the completion of post-incident tasks, including the cleanup process and the preparation of a comprehensive incident report detailing the incident's cause, impact, and resolution actions.

10. Records and Reporting

The ISMS Team shall continuously assess the duration and evolving nature of the incident, ensuring that all relevant parties are kept informed and that the business-critical needs of the organization are met. The ISMS Team will hold regular meetings to reassess the situation, monitor the execution of the incident response plan, and maintain communication with key stakeholders, including employees, senior management, and third parties, until the emergency is resolved or mitigated in accordance with organizational procedures and legal obligations.

The ISMS Team shall prepare an incident report in a predefined format, detailing key information such as the time the incident first impacted the organization, the time of detection, the time the impact was resolved, and the lessons learned from the incident. The internal report will include a summary of the incident, an assessment of its impact, and confirmation that the incident has been resolved.

The external report will be generated as necessary and will include information regarding the restoration of services, should this information be required by customers or other external stakeholders.

11. Review of the Information Security Continuity

The ISMS Team shall document and generate comprehensive reports for each incident. Following the resolution of every incident, the Incident Response Plan shall be reviewed and evaluated to identify any deficiencies and to implement corrective actions to prevent the recurrence of similar events in the future. A risk assessment will be conducted to assess the current infrastructure and any potential changes. Any necessary modifications to the setup will be discussed in the review meeting, and employees will be provided with training as deemed necessary to ensure compliance with updated procedures and mitigate future risks.

12. Contact

If you would like to contact us with questions or concerns about our privacy policies and practices, you may contact us via any of the following methods:

Team Responsibility
hr@xecurify.com Communication Activities throughout the events.
operations@xecurify.com Take necessary actions for the normal business operations.
info@xeurify.com Implementation of Incident Response Plan