Incident Response Plan

Zielgruppe: Security-Teams · Management Status: Aktiv

Version: 1.0 Last Updated: February 2026 Owner: Nova IAM Security Team


1. Purpose

This plan defines the procedures for detecting, responding to, and recovering from security incidents affecting Nova IAM deployments.

2. Incident Classification

Severity Levels

Level Definition Examples Response Time
P1 — Critical Active breach, data exfiltration, or system compromise Unauthorized data access, credential theft, ransomware Immediate (< 1 hour)
P2 — High Vulnerability actively exploited or imminent threat Authentication bypass, SQL injection attempt, privilege escalation < 4 hours
P3 — Medium Security weakness discovered, no active exploitation Misconfiguration, expired certificates, failed audit controls < 24 hours
P4 — Low Minor security improvement or informational finding Log anomaly, policy deviation, dependency update needed < 1 week

3. Incident Response Phases

Phase 1: Detection & Identification

Goal: Determine if a security event constitutes an incident.

Detection sources:

  • Nova IAM audit log anomalies (unusual login patterns, bulk role changes, off-hours activity)
  • Infrastructure monitoring alerts (CPU, memory, network anomalies)
  • User/customer reports
  • Automated vulnerability scans
  • Third-party threat intelligence

Identification steps:

  1. Review audit log entries: GET /api/audit?category=auth and related endpoints
  2. Check for unauthorized session activity
  3. Verify integrity of role assignments and user data
  4. Assess scope: which users, systems, and data may be affected

Phase 2: Containment

Goal: Limit the impact of the incident.

Immediate containment:

  • Disable compromised user accounts (set status to inactive)
  • Revoke active sessions by rotating the SECRET_KEY
  • Block suspicious IP addresses at the network/firewall level
  • Disconnect affected backend system integrations if provisioning is compromised

Short-term containment:

  • Isolate the affected deployment (network segmentation)
  • Preserve audit logs and database snapshots for forensic analysis
  • Enable enhanced logging if not already active

Phase 3: Eradication

Goal: Remove the root cause.

  • Patch the vulnerability or close the attack vector
  • Rotate all potentially compromised credentials:
    • Database passwords
    • Flask SECRET_KEY
    • Backend system connection credentials (SAP, LDAP, Entra)
    • AI provider API keys
  • Review and remove any unauthorized user accounts or role assignments
  • Verify database integrity via referential constraint checks

Phase 4: Recovery

Goal: Restore normal operations.

  • Restore from verified clean backup if data integrity is compromised
  • Re-enable backend system connections with fresh credentials
  • Monitor audit logs intensively for 72 hours post-recovery
  • Verify all user assignments match expected state
  • Run reconciliation checks against backend systems

Phase 5: Post-Incident Review

Goal: Learn and improve.

Within 5 business days of resolution:

  1. Document timeline of events
  2. Identify root cause and contributing factors
  3. Assess effectiveness of detection and response
  4. Update security controls to prevent recurrence
  5. Brief affected customers with:
    • What happened
    • What data was affected
    • What actions were taken
    • What changes are being made
  6. Update this plan if gaps were identified

4. Communication

Internal Communication

Stakeholder When Method
Security team Immediately Direct message / call
Engineering lead Within 1 hour (P1-P2) Direct message / call
Management Within 4 hours (P1) Email + call

External Communication

Stakeholder When Method
Affected customers Within 72 hours of confirmed breach Email with incident report
Supervisory authority Within 72 hours (if GDPR applies) Formal notification
Public disclosure After containment, if required Security advisory

5. Audit Log Forensics

Nova IAM's audit log supports incident investigation with these queries:

Investigation Need Audit Log Filter
Suspicious logins event_type = 'login', check IP addresses and timestamps
Unauthorized role changes category = 'roles', compare actor_id against authorized admins
Bulk operations event_type patterns with high frequency in short timeframes
Specific user activity Filter by actor_id or target_id
After-hours activity Filter by timestamp outside business hours

6. Contact Information

Role Contact
Security Lead security@nova-iam.com
On-Call Engineer oncall@nova-iam.com
Data Protection Contact (no DPO appointed) privacy@nova-iam.com
Fragen zu diesem Dokument? Schreiben Sie an trust@nova-iam.com – wir bestätigen den Eingang innerhalb von 2 Werktagen.