Model policy · version 1
Incident Response
Know what to do in the first hour of a breach or outage, who decides, and who has to be told by when. The sponsor bank owes its regulator a 36-hour notice, so your clock is shorter than you think, and the incident log is what proves you met it.
What’s in this policy12 sections · Incident Response · Read the full policy
9Obligations · things you must do
19Evidence · records that prove it
1Monitoring · checks and deadlines
2Reporting · reports you must send
Does this apply to you?
Answer a few questions and each obligation is marked applies, likely, or needs more information.
Tell Leela about your companyHand over the whole policy
Every obligation in this policy, in one request.
What the policy requires
Automate
Leela can perform the work through your connected systems.
Monitor
Leela can watch for the trigger, keep the clock, and flag what is late.
Prepare for review
Leela can prepare the artifact and hand it to a person for review.
Human required
A person must do the work; Leela can track it and file the evidence.
TriggerEvent-driven · Each reported or suspected incident, the same business day
EvidenceIncident record, Team activation notice
TriggerEvent-driven · Each confirmed incident: 30 minutes for Critical, 2 hours for High, 8 business hours for Moderate
EvidenceContainment log, Recovery sign-off
TriggerEvent-driven · Immediately on a breach; within 4 hours of confirming a Critical incident; daily until resolved; closure report within 10 business days
EvidenceSponsor bank notice, Update log, Incident closure report
TriggerEvent-driven · As soon as possible after determining a disruption of 4 hours or more has occurred or is reasonably likely
EvidenceDetermination record, Bank notice
TriggerEvent-driven · Each incident exposing customer data, typically within 5 to 10 business days of confirmation
EvidenceNotification decision, Customer notice
TriggerEvent-driven · Each incident exposing personal information, within each applicable state’s deadline; each bank-made notice, on the bank’s timeline
EvidenceCounsel determination, Regulatory notice file
TriggerEvent-driven · Each High or Critical incident, within 5 business days of containment; findings shared within 30 days of closure
EvidenceLessons-learned record, Remediation tracker
TriggerAnnual · Once a year, with the plan update that follows; sooner on material change
EvidenceTabletop exercise report, Plan revision record
TriggerContinuous · Each incident at detection; records kept seven years from closure
EvidenceIncident log, Retention schedule entry