Specification de controle
Incident evidence chain preservation
Threat Response Automation
Incident evidence chain preservation defines an enforceable control requirement inside Threat Response Automation, with measurable checkpoints and operational constraints.
Objectif
Enforce policy and runtime constraints tied to Threat Response Automation so drift and non-compliant operations are blocked early.
Contexte de perimetre
Detection and response loop with automated triage and controlled containment.
Entrees
- Policy requirements and risk appetite definition
- System boundaries and affected components
- Exception handling workflow and escalation owner
Sorties
- Control implementation with enforceable policy condition
- Monitoring signal and alerting threshold
- Exception register entry with expiry and audit trace
Criteres d acceptation
- Control blocks or flags non-compliant state changes
- Evidence is exportable for internal or external audit
- Exception path is time-bounded and explicitly approved
Notes de preuve de conformite
- [NIS2] Control objective and test outcome recorded for assurance
- [DORA] Control objective and test outcome recorded for assurance
Schema de specification
Role responsable
Security and Platform Governance Owner
Validation finale
Governance lead plus founder-level exception approval for bypasses
Politique de versioning
Policy revision tags linked to deployment release ID
Cadence de revue
Bi-weekly control health review and quarterly deep audit
Retention des preuves
Control test evidence retained for at least 18 months
Sections obligatoires
- Control objective and policy statement
- Trigger conditions and enforcement mechanism
- Monitoring signals and alert thresholds
- Exception process with expiry policy
- Control test method and result capture format