Incident Response and Continuity
If you have any questions about this policy, please contact the InfoSec team at security@accucodeai.com.
If you have any questions about this policy, please contact the InfoSec team at security@accucodeai.com.
AccuCode AI Inc. is committed to maintaining the availability and integrity of its systems, data, and services. This Disaster Recovery (DR) Plan Policy outlines the strategies, procedures, and responsibilities necessary to effectively respond to and recover from a disruptive event or disaster that impacts our IT infrastructure and business operations.
The purpose of this policy is to minimize the impact of a disaster on our ability to serve customers and protect the company’s assets and reputation. It provides a framework for restoring critical systems and resuming normal operations in a timely manner.
All employees are expected to familiarize themselves with this policy and their individual roles and responsibilities in the event of a disaster. The InfoSec team will maintain, test, and update this DR plan on a regular basis.
If you have any questions about this policy, please contact the InfoSec team at security@accucodeai.com.
Version1.0.3 Last Updated2024-01-31 APPROVED
AccuCode AI Inc. recognizes the importance of having a robust Disaster Recovery Plan (DRP) to ensure business continuity and minimize the impact of any disaster or major outage on our operations. This policy outlines the requirements for developing, implementing, and maintaining a comprehensive DRP.
The purpose of this policy is to establish a baseline for creating and maintaining a DRP that describes the process to recover IT systems, applications, and data from any type of disaster causing a major outage. The DRP aims to minimize the impact of disasters on our business operations and protect the confidentiality, integrity, and availability of our clients’ data.
This policy applies to all IT management staff responsible for developing, testing, and updating the DRP. The policy focuses on the requirement to have a DRP and does not provide specific requirements for the content of the plan or its subplans.
The following contingency plans must be created as part of the DRP:
All client data backups must be encrypted with the same strong, client-specific encryption used for data at rest. Backups should be retained for 180 days and securely destroyed thereafter. To protect against ransomware, AccuCode AI Inc. employs:
After creating the plans, it is important to practice them to the extent possible. Management should set aside time to test the implementation of the DRP. Table-top exercises should be conducted annually to discover and correct issues that may cause the plan to fail in an environment with few consequences. The DRP should be reviewed and updated on an annual basis at a minimum.
The InfoSec team will verify compliance to this policy through various methods, including but not limited to, periodic walk-throughs, video monitoring, business tool reports, internal and external audits, and feedback to the policy owner.
Any exception to the policy must be approved by the InfoSec team in advance.
An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
The Incident Response (IR) plan outlines AccuCode AI’s process for preparing for, detecting, responding to, and recovering from information security incidents. The goal is to minimize impact to the business and protect the confidentiality, integrity and availability of data and systems.
Key components of the IR plan include:
All employees are required to immediately report suspected security incidents to the InfoSec team at security@accucodeai.com. The IR plan will be tested annually and updated as needed.
Version1.0.0 Last Updated2024-03-29 APPROVED
The purpose of this Computer Emergency Response Plan is to outline the procedures and actions to be taken in the event of a computer emergency or security incident at AccuCode AI Inc. This plan is designed to minimize the impact of such incidents on the company’s operations, protect sensitive healthcare data, and ensure the timely restoration of critical systems and services.
This plan applies to all employees, contractors, and third-party vendors who have access to AccuCode AI Inc.’s computer systems, networks, and data.
In the event of a computer emergency or security incident, the following steps should be taken:
Immediately notify the InfoSec team by emailing security@accucodeai.com or calling the Engineering team lead.
Provide a detailed description of the incident, including the date and time it occurred, the systems and data affected, and any actions taken so far.
Do not attempt to investigate or resolve the incident on your own, as this may compromise the integrity of the investigation and recovery efforts.
The Incident Response Team (IRT) is responsible for managing and coordinating the response to computer emergencies and security incidents. The team consists of the following members:
Upon receiving a report of a computer emergency or security incident, the IRT will:
Incidents will be classified according to the following severity levels:
During an incident, the IRT will provide regular updates to management and affected stakeholders via email, phone, or in-person meetings, as appropriate. The frequency and method of communication will depend on the severity of the incident and the needs of the stakeholders.
After an incident has been resolved, the IRT will conduct a post-incident review to:
This Computer Emergency Response Plan will be reviewed and updated annually, or more frequently as needed, to ensure that it remains current and effective. All employees, contractors, and third-party vendors will be trained on the plan and their roles and responsibilities in the event of an incident.
Version1.0.3 Last Updated2023-10-16 APPROVED
The Incident Response Plan Policy provides a framework for the InfoSec team and business units at AccuCode AI Inc. to collaborate effectively in managing and responding to security incidents. This policy ensures that when a security vulnerability is identified or exploited, the organization can swiftly mitigate and remediate the issue. The Incident Response Plan (IRP) defines the product description, contact information, escalation paths, expected service level agreements (SLA), severity and impact classification, and mitigation/remediation timelines.
The purpose of this policy is to establish the requirement for all business units supported by the InfoSec team to develop and maintain an Incident Response Plan. This ensures that the security incident management team has all the necessary information to formulate a successful response when a specific security incident occurs.
This policy applies to all established and defined business units or entities within AccuCode AI Inc.
The development, implementation, and execution of an Incident Response Plan (IRP) are the primary responsibility of the specific business unit for which the IRP is being developed, in cooperation with the InfoSec team. Business units are expected to properly facilitate the IRP for services or products they are accountable for. The business unit security coordinator or champion is further expected to work with the InfoSec team in the development and maintenance of the Incident Response Plan.
The product description in an IRP must clearly define the service or application to be deployed, with additional attention to data flows, logical diagrams, and architecture, which are considered highly useful.
The IRP must include contact information for dedicated team members to be available during non-business hours should an incident occur and escalation be required. This may be a 24/7 requirement depending on the defined business value of the service or product, coupled with the impact on customers. The IRP document must include all phone numbers and email addresses for the dedicated team member(s).
The IRP must define triage steps to be coordinated with the security incident management team in a cooperative manner with the intended goal of swift security vulnerability mitigation. This step typically includes validating the reported vulnerability or compromise.
The IRP must include a defined process for identifying and testing mitigations prior to deployment. These details should include both short-term mitigations and the remediation process.
The IRP must include levels of response to identified vulnerabilities that define the expected timelines for repair based on severity and impact to consumers, brand, and company. These response guidelines should be carefully mapped to the level of severity determined for the reported vulnerability.
Each business unit must be able to demonstrate they have a written IRP in place, and that it is under version control and available via the web. The policy should be reviewed annually.
Any exception to this policy must be approved by the InfoSec team in advance and have a written record.
Any business unit found to have violated this policy (no IRP developed prior to service or product deployment) may be subject to delays in service or product release until such a time as the IRP is developed and approved. Responsible parties may be subject to disciplinary action, up to and including termination of employment, should a security incident occur in the absence of an IRP.