This policy establishes Calenix's framework for identifying, assessing, containing, investigating, remediating and learning from security incidents.
An incident is any confirmed or suspected event that compromises the confidentiality, integrity, or availability of the Service or customer data.
A security incident may include:
Calenix's objectives are to:
Incidents may be classified according to:
Calenix generally follows these stages:
Potential incidents are identified through:
The incident is evaluated to determine:
Calenix may:
Calenix may analyse:
Calenix addresses the underlying cause, which may include:
Systems are restored to normal operation after appropriate security checks.
Material incidents may be reviewed to identify:
Where required by applicable law or contractual obligations, Calenix will notify affected customers or individuals of qualifying incidents.
Notifications may include, where reasonably available:
Calenix may delay notification where legally permitted and reasonably necessary to avoid compromising an investigation, security response or legal obligation.
Where an incident occurs at a third-party provider that affects Calenix or customer information, Calenix will assess the provider's notification and remediation information and take reasonable steps to mitigate resulting risk.
Calenix may preserve relevant records and evidence necessary for:
Incident information is shared internally on a need-to-know basis and externally only where appropriate or required.
Material incidents may result in updates to: