LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Incident Response Policy

Public security and assurance reference

POL-17: Incident Response Policy

Purpose

This policy establishes the framework for responding to security incidents. It ensures that legal-medical knowledge and analysis services are protected against threats and that incidents are handled effectively.

Scope

This policy applies to all LNC Nexus hosted, private, and self-managed deployments. It covers all security incidents and breaches.

Policy Statements

Security incidents shall be identified, reported, and responded to promptly. Incident response plans must be tested regularly. In self-managed deployments, customers are responsible for their own incident response; LNC Nexus provides the framework but not the enforcement. Regulated data handling requires additional incident response measures. No incident shall be ignored without explicit justification.

Roles and Responsibilities

The Security Team defines incident response standards and monitors compliance. Incident response teams handle incidents. Department heads ensure compliance in their areas. Users report suspected incidents.

Evidence and Review

Incident logs, response records, and audit reports serve as evidence of compliance. The Security Team conducts periodic reviews of incident response practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Access may be suspended immediately upon detection of a violation.

POL-4 (Vulnerability Management Policy), POL-10 (Audit Logging Policy), POL-12 (Business Continuity Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft