Incidents
This page's purpose is to report, review and follow incidents within CAcert.
Definitions
An incident is an event that could lead to loss of, or disruption to CAcert's operations, services or functions. If not handled it can escalate into an emergency, crisis or a disaster.
The incident management is therefore a process driven by CAcert's internal audit team to limit the potential disruption caused by such an event, followed by a return to normal business.
Incidents could effect one ore more of the following:
- Operations
- Information Security
- IT systems
- CAcert Office bearers
- Community
Process
- Incident Report
- Incident Classification
- Incident Handling with an Incident Response Team consisting of required functions within CAcert
- Incident Documentation and strategies to avoid further occurrence
- Incident Communication to CAcert's Management
Report an incident
If you have the feeling or a proof that something in the community does not comply to the internal rules, please send an e-mail to <audit AT SPAMFREE cacert DOT org> to contact the audit team.
Try to be as precise as possible with your incident and add a proof where possible. All cases will be handled anonymously, the audit team will never reveal your identity without your confirmation. We need to follow every hint.
'Beware:' The Incident Reporting is no substitution for a proper Arbitration case. Even Arbitration might get involved into the incidents to provide required information under privacy, we do not handle any arbitration cases.
Lists of Incidents
{-} red open - orange running - {0} yellow execution - {g} green closed
Incident Nr. |
Incident Manager |
Status |
Synopsis |
running |
Association rule violations |
||
{g} closed |
Potential Abuse of Power |
||
{0} execution |
Data Privacy breach |
||
{-} open |
Signer security issue |
||
{-} open |
Missing document |
||
{g} closed |
Data Privacy breach |
||
{g} closed |
Wrong Version of CCA deployed |
||
{g} closed |
Support Team not following established process |
||
{0} execution |
Attempted Privacy data breach |
||
{0} execution |
Data Privacy breach |
||
{0} execution |
Data Privacy breach & potential abuse of power |
||
{g} closed |
Potential abuse of power |
||
{g} closed |
Potential loss of CAcert Root Certificate credentials |
Incident Template
|
|
{-} init |
template for an incident. |
type i201YMMDD.n :