Incident Response Plan
Version: 1.0 Last Updated: February 2026 Owner: Nova IAM Security Team
1. Purpose
This plan defines the procedures for detecting, responding to, and recovering from security incidents affecting Nova IAM deployments.
2. Incident Classification
Severity Levels
| Level | Definition | Examples | Response Time |
|---|---|---|---|
| P1 — Critical | Active breach, data exfiltration, or system compromise | Unauthorized data access, credential theft, ransomware | Immediate (< 1 hour) |
| P2 — High | Vulnerability actively exploited or imminent threat | Authentication bypass, SQL injection attempt, privilege escalation | < 4 hours |
| P3 — Medium | Security weakness discovered, no active exploitation | Misconfiguration, expired certificates, failed audit controls | < 24 hours |
| P4 — Low | Minor security improvement or informational finding | Log anomaly, policy deviation, dependency update needed | < 1 week |
3. Incident Response Phases
Phase 1: Detection & Identification
Goal: Determine if a security event constitutes an incident.
Detection sources:
- Nova IAM audit log anomalies (unusual login patterns, bulk role changes, off-hours activity)
- Infrastructure monitoring alerts (CPU, memory, network anomalies)
- User/customer reports
- Automated vulnerability scans
- Third-party threat intelligence
Identification steps:
- Review audit log entries:
GET /api/audit?category=authand related endpoints - Check for unauthorized session activity
- Verify integrity of role assignments and user data
- Assess scope: which users, systems, and data may be affected
Phase 2: Containment
Goal: Limit the impact of the incident.
Immediate containment:
- Disable compromised user accounts (set status to
inactive) - Revoke active sessions by rotating the
SECRET_KEY - Block suspicious IP addresses at the network/firewall level
- Disconnect affected backend system integrations if provisioning is compromised
Short-term containment:
- Isolate the affected deployment (network segmentation)
- Preserve audit logs and database snapshots for forensic analysis
- Enable enhanced logging if not already active
Phase 3: Eradication
Goal: Remove the root cause.
- Patch the vulnerability or close the attack vector
- Rotate all potentially compromised credentials:
- Database passwords
- Flask SECRET_KEY
- Backend system connection credentials (SAP, LDAP, Entra)
- AI provider API keys
- Review and remove any unauthorized user accounts or role assignments
- Verify database integrity via referential constraint checks
Phase 4: Recovery
Goal: Restore normal operations.
- Restore from verified clean backup if data integrity is compromised
- Re-enable backend system connections with fresh credentials
- Monitor audit logs intensively for 72 hours post-recovery
- Verify all user assignments match expected state
- Run reconciliation checks against backend systems
Phase 5: Post-Incident Review
Goal: Learn and improve.
Within 5 business days of resolution:
- Document timeline of events
- Identify root cause and contributing factors
- Assess effectiveness of detection and response
- Update security controls to prevent recurrence
- Brief affected customers with:
- What happened
- What data was affected
- What actions were taken
- What changes are being made
- Update this plan if gaps were identified
4. Communication
Internal Communication
| Stakeholder | When | Method |
|---|---|---|
| Security team | Immediately | Direct message / call |
| Engineering lead | Within 1 hour (P1-P2) | Direct message / call |
| Management | Within 4 hours (P1) | Email + call |
External Communication
| Stakeholder | When | Method |
|---|---|---|
| Affected customers | Within 72 hours of confirmed breach | Email with incident report |
| Supervisory authority | Within 72 hours (if GDPR applies) | Formal notification |
| Public disclosure | After containment, if required | Security advisory |
5. Audit Log Forensics
Nova IAM's audit log supports incident investigation with these queries:
| Investigation Need | Audit Log Filter |
|---|---|
| Suspicious logins | event_type = 'login', check IP addresses and timestamps |
| Unauthorized role changes | category = 'roles', compare actor_id against authorized admins |
| Bulk operations | event_type patterns with high frequency in short timeframes |
| Specific user activity | Filter by actor_id or target_id |
| After-hours activity | Filter by timestamp outside business hours |
6. Contact Information
| Role | Contact |
|---|---|
| Security Lead | security@nova-iam.com |
| On-Call Engineer | oncall@nova-iam.com |
| Data Protection Contact (no DPO appointed) | privacy@nova-iam.com |
Fragen zu diesem Dokument? Schreiben Sie an
trust@nova-iam.com –
wir bestätigen den Eingang innerhalb von 2 Werktagen.