Security Compliance

IR.2.02 - Incident Reporting

Control Statement

IllumiDesk provides a contact method for external parties to:

  • Submit complaints and inquiries

  • Report incidents

Context

Having an easily accessible and public channel for external parties to contact IllumiDesk in the event of a security incident provides a way for the community to help IllumiDesk keep its systems safe and to faster identify and respond to security incidents internally. This control can be tested by means of citing sufficient documentation with respect to emergency contacts and on-call engineers to support when an incident occurs, and to see if this documentation is easily available.

Scope

This control applies to IllumiDesk.com

Ownership

  • Control Owner: Corporate Compliance

  • Process owner(s):

    • Security Operations

    • Infrastructure

    • Legal

Additional control information and project tracking

Non-public information relating to this security control as well as links to the work associated with various phases of project work can be found in the Incident Reporting Contact Information control issue.

Examples of evidence an auditor might request to satisfy this control:

  • Handbook pages that provide external parties a contact method

  • Link to the IllumiDesk-foss issue tracker and samples of relevant issues reporting incidents

Policy Reference

IllumiDesk provides a contact method for external parties to:

Submit complaints and inquiries

  • Incident Management

  • Support Team function in the handbook

  • Support page contains information to contact the Support team

  • Security Incident Communications Plan

Report incidents

  • Process for engaging security on-call

  • Security operations on-call guide

  • Security Incident Communications Plan

IllumiDesk IR Contact information in the Handbook

  • Information on how to contact the IllumiDesk legal team

  • IllumiDesk maintains current contact information for external parties to report Security incidents

  • All other inquiries and reports can be made on the IllumiDesk-ce issue tracker

Framework Mapping

  • SOC2 CC

    • CC2.3