Incident Response
DRAFT — process pending formalisation (Phase 4).
- Detection: application logging and the immutable audit log support investigation of suspected incidents.
- Containment: affected access can be revoked (support grants are time-boxed; sessions/roles are revocable).
- Notification: on a confirmed personal-data breach we notify the affected Controller(s) without undue delay so they can meet the 72-hour regulator clock; we assist their assessment.
- Records: incidents and actions are recorded; a formal incident-report system with severity and escalation is planned in Phase 4.
Report a suspected incident to MyEdMentor via the channel in your signed agreement.