IR.2.02 - Incident Reporting
Control Statement
IllumiDesk provides a contact method for external parties to:
Submit complaints and inquiries
Report incidents
Context
Having an easily accessible and public channel for external parties to contact IllumiDesk in the event of a security incident provides a way for the community to help IllumiDesk keep its systems safe and to faster identify and respond to security incidents internally. This control can be tested by means of citing sufficient documentation with respect to emergency contacts and on-call engineers to support when an incident occurs, and to see if this documentation is easily available.
Scope
This control applies to IllumiDesk.com
Ownership
Control Owner:
Corporate Compliance
Process owner(s):
Security Operations
Infrastructure
Legal
Additional control information and project tracking
Non-public information relating to this security control as well as links to the work associated with various phases of project work can be found in the Incident Reporting Contact Information control issue.
Examples of evidence an auditor might request to satisfy this control:
Handbook pages that provide external parties a contact method
Link to the
IllumiDesk-foss
issue tracker and samples of relevant issues reporting incidents
Policy Reference
IllumiDesk provides a contact method for external parties to:
Submit complaints and inquiries
Incident Management
Support Team function in the handbook
Support page contains information to contact the Support team
Security Incident Communications Plan
Report incidents
Process for engaging security on-call
Security operations on-call guide
Security Incident Communications Plan
IllumiDesk IR Contact information in the Handbook
Information on how to contact the IllumiDesk legal team
IllumiDesk maintains current contact information for external parties to report Security incidents
All other inquiries and reports can be made on the IllumiDesk
-ce
issue tracker
Framework Mapping
SOC2 CC
CC2.3
Last updated