CONFIDENTIAL // INTERNAL & AUTHORIZED PARTNER USE ONLY
Security Operations Center • Active

Incident Response Protocol

Standardized framework for detecting, responding to, and recovering from security incidents across all Aevum Zenth divisions. Aligned with NIST SP 800-61 & ISO 27035.

Version: 4.2.1 Last Updated: 2026-03-14 Owner: CISO Office Classification: Internal/Partner

6-Phase Incident Lifecycle

All incidents must follow this structured lifecycle to ensure consistent handling, legal preservation, and operational continuity.

01
🛡️

Preparation

Establish IR teams, maintain tooling, update playbooks, and conduct quarterly tabletop exercises across divisions.

  • Validate contact matrices
  • Verify forensic imaging tools
  • Review division-specific runbooks
02
🔍

Identification

Detect anomalies, validate alerts, classify severity, and initiate IR ticket within SLA windows.

  • Correlate SIEM/SOAR logs
  • Confirm false positive vs true incident
  • Assign initial severity tier
03
🛑

Containment

Isolate affected systems, block malicious IOCs, preserve evidence, and prevent lateral movement.

  • Network segmentation enforcement
  • Account credential rotation
  • Evidence chain-of-custody logging
04
🔥

Eradication

Remove root cause, patch vulnerabilities, hunt for persistence mechanisms, and validate clean state.

  • Malware removal & host hardening
  • Vulnerability remediation
  • Threat hunting sweep
05
🔄

Recovery

Restore systems from verified backups, monitor for reinfection, and gradually return to normal operations.

  • Controlled system restoration
  • Enhanced monitoring window (72h)
  • Business continuity validation
06
📊

Lessons Learned

Conduct post-incident review, update playbooks, report to governance, and track remediation actions.

  • IR post-mortem within 5 business days
  • Update detection rules & runbooks
  • Executive summary distribution

Severity Classification & SLAs

Incidents are classified based on business impact, data sensitivity, and scope. Response times are measured from ticket creation.

Severity Definition Response SLA Escalation Path
● Critical Active breach, ransomware, PII/PHI exposure, core infrastructure compromise 15 minutes SOC L2 → CIRT → CISO → CEO/Legal
● High Unauthorized access, privilege escalation, DDoS impacting revenue systems 1 hour SOC L2 → Division Security Lead → CISO Office
● Medium Policy violations, suspicious lateral movement, non-critical malware 4 hours SOC L1 → SOC L2 → Ticket Resolution
● Low Benign probes, failed auth spikes, non-sensitive alert noise 24 hours Automated triage → SOC L1 → Archive

Escalation & Contact Matrix

Authorized personnel only. All communications must use encrypted channels.

🌍 Global SOC

  • 24/7 Hotline +1 (800) 555-IRPT
  • Secure Email soc@secure.aevumzenth.io
  • Portal /soc-tickets

⚖️ Legal & Compliance

  • Data Protection dpo@aevumzenth.com
  • Incident Counsel legal-ir@aevumzenth.com
  • Regulatory Filing /compliance-portal

🏢 Division Leads

  • Energy & Power energy-sec@az.com
  • Digital Systems tech-sec@az.com
  • Health Sciences health-sec@az.com

🔒 Report a Security Incident

All external parties and internal staff must use the encrypted channel below. Unencrypted reports containing sensitive data will be rejected.

PGP Fingerprint: A8F2 9B41 C3D0 E7F2 1A5B 8C9D 4E6F 2B3A 7C0D 9E1F

Compliance Alignment

This protocol maintains continuous alignment with global security standards and regulatory requirements.

📘

NIST SP 800-61

Computer Security Incident Handling Guide

🛡️

ISO 27035:2024

Information Security Incident Management

\n
⚖️

GDPR / CCPA

Data Breach Notification Requirements

🏛️

SOC 2 Type II

Security & Availability Criteria