← All 21 policies
This page is the rule, not the implementation. It states what Revique
must do, at or above the PCI DSS minimum. How Revique actually does it today — the real AWS configuration, the current values, and where an auditor logs in to verify them — is in
Procedure 03. Values shown as [X] are placeholders still to be set.
Purpose
To ensure that every suspected or confirmed security incident or data breach is detected, reported, contained, investigated, and resolved through a defined, repeatable process, and that required parties are notified within mandated timeframes.
Scope
Applies to all security incidents affecting Revique systems, data (CHD/PHI), personnel, and third-party services, in any environment.
Policy statements
Each statement below is mandatory. The bolded must marks the obligation.
1Revique must maintain a documented incident response plan that is tested at least annually.
2Any suspected or confirmed incident or breach must be reported immediately through the defined reporting channel.
3An incident response team with defined roles must be designated and available 24/7.
4Every incident must be classified by severity and handled according to defined containment, eradication, and recovery steps.
5Suspected compromises of CHD/PHI must trigger the breach-notification procedure, including notifying affected parties and regulators within the legally required timeframe.
6Every incident must be documented, and a post-incident review must be conducted to identify root cause and preventive actions.
7Monitoring and alerting must be in place to support timely detection of incidents.
8Incident records must be retained for at least [X] months.
Roles & responsibilities
| Role | Responsibility |
|---|
| All Personnel | Report suspected incidents immediately. |
| Incident Response Team | Contain, investigate, and resolve incidents per the plan. |
| Security Officer | Coordinate response, breach notification, and post-incident review. |
Enforcement
This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.
⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→