Incident & governance
An internal platform is unavailable. An administrator account shows an unusual sign-in. You are part of the decision team.
The first minutes
You do not yet know whether the outage and sign-in are related. What is your first proposal?
Bring in the accountable teams, contain the suspect account and preserve useful evidence.
Coordination helps define containment with operations. Preserving evidence supports investigation. Rebuilding everything too soon may remove useful information.
Useful evidence: Timestamps, account, affected systems and containment decision.
Pressure to restore
A backup is available. The business wants immediate recovery. What must be established?
That the backup is usable and restoration can be checked in a controlled environment.
A backup’s existence proves neither integrity nor recovery capability. Define technical and business checks, then validate the restoration result.
Useful evidence: Restoration report, integrity checks and business validation.
Accepting remaining risk
The service can restart with a temporary control. A weakness remains open. How should the decision be handled?
Have the authorized risk owner approve it with an action, an owner and a review date.
The decision belongs to the risk owner. Explicit scope, ownership and a review date make a temporary measure traceable.
Useful evidence: Dated decision, residual risk, owner and deadline.
