Incident Response Protocol
Standardized framework for detecting, responding to, and recovering from security incidents across all Aevum Zenth divisions. Aligned with NIST SP 800-61 & ISO 27035.
6-Phase Incident Lifecycle
All incidents must follow this structured lifecycle to ensure consistent handling, legal preservation, and operational continuity.
Preparation
Establish IR teams, maintain tooling, update playbooks, and conduct quarterly tabletop exercises across divisions.
- Validate contact matrices
- Verify forensic imaging tools
- Review division-specific runbooks
Identification
Detect anomalies, validate alerts, classify severity, and initiate IR ticket within SLA windows.
- Correlate SIEM/SOAR logs
- Confirm false positive vs true incident
- Assign initial severity tier
Containment
Isolate affected systems, block malicious IOCs, preserve evidence, and prevent lateral movement.
- Network segmentation enforcement
- Account credential rotation
- Evidence chain-of-custody logging
Eradication
Remove root cause, patch vulnerabilities, hunt for persistence mechanisms, and validate clean state.
- Malware removal & host hardening
- Vulnerability remediation
- Threat hunting sweep
Recovery
Restore systems from verified backups, monitor for reinfection, and gradually return to normal operations.
- Controlled system restoration
- Enhanced monitoring window (72h)
- Business continuity validation
Lessons Learned
Conduct post-incident review, update playbooks, report to governance, and track remediation actions.
- IR post-mortem within 5 business days
- Update detection rules & runbooks
- Executive summary distribution
Severity Classification & SLAs
Incidents are classified based on business impact, data sensitivity, and scope. Response times are measured from ticket creation.
| Severity | Definition | Response SLA | Escalation Path |
|---|---|---|---|
| ● Critical | Active breach, ransomware, PII/PHI exposure, core infrastructure compromise | 15 minutes | SOC L2 → CIRT → CISO → CEO/Legal |
| ● High | Unauthorized access, privilege escalation, DDoS impacting revenue systems | 1 hour | SOC L2 → Division Security Lead → CISO Office |
| ● Medium | Policy violations, suspicious lateral movement, non-critical malware | 4 hours | SOC L1 → SOC L2 → Ticket Resolution |
| ● Low | Benign probes, failed auth spikes, non-sensitive alert noise | 24 hours | Automated triage → SOC L1 → Archive |
Escalation & Contact Matrix
Authorized personnel only. All communications must use encrypted channels.
🌍 Global SOC
- 24/7 Hotline +1 (800) 555-IRPT
- Secure Email soc@secure.aevumzenth.io
- Portal /soc-tickets
⚖️ Legal & Compliance
- Data Protection dpo@aevumzenth.com
- Incident Counsel legal-ir@aevumzenth.com
- Regulatory Filing /compliance-portal
🏢 Division Leads
- Energy & Power energy-sec@az.com
- Digital Systems tech-sec@az.com
- Health Sciences health-sec@az.com
🔒 Report a Security Incident
All external parties and internal staff must use the encrypted channel below. Unencrypted reports containing sensitive data will be rejected.
Compliance Alignment
This protocol maintains continuous alignment with global security standards and regulatory requirements.
NIST SP 800-61
Computer Security Incident Handling Guide
ISO 27035:2024
Information Security Incident Management
GDPR / CCPA
Data Breach Notification Requirements
SOC 2 Type II
Security & Availability Criteria