1. Objectives and scope
Incident response covers suspected compromise, unauthorized access, material data loss, service disruption, malicious activity, credential exposure and significant provider incidents affecting FormEsque systems or customer data.
2. Detection and reporting
Signals may come from structured application logs, provider alerts, webhook failures, audit records, users or security researchers. Reports are recorded, time-stamped, assigned an owner and triaged for affected environments, tenants, confidentiality, integrity and availability.
3. Severity and escalation
Severity reflects customer impact, sensitivity, scope, exploitability and duration. Events with suspected unauthorized production access, signed-document integrity impact, exposed credentials or broad outage receive immediate escalation. Lower-severity operational defects remain tracked until resolved.
4. Containment and preservation
Responders may revoke credentials and sessions, isolate services, disable affected features, block abusive traffic, preserve relevant logs and snapshots, and limit access while investigation continues. Evidence handling should minimize changes and maintain a clear timeline.
5. Eradication and recovery
Recovery includes removing the cause, rotating affected secrets, patching code or configuration, validating tenant boundaries, restoring verified data where necessary, monitoring for recurrence and progressively returning service. Restored databases must be reconciled with migration history before use.
6. Notification
FormEsque will notify affected customers and authorities when required by applicable law or contract. Notices are based on verified facts and may be updated as investigation continues. They should describe known impact, relevant timing, containment and recommended customer actions without exposing another tenant or compromising the response.
7. Post-incident improvement
Material incidents receive a documented review covering root cause, timeline, response effectiveness, customer impact and corrective actions. Owners and target dates are assigned, and lessons are incorporated into testing, monitoring, access controls, backups and release procedures.
