Simulated workplaceCAQA Nova Digital Systems is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
ICTCAQA NovaSimulated workplace
Back to library
CAQA Nova Digital Systems · Simulated workplace

Cyber Security Incident Response Procedure

ProcedureControlled document
NOV-PRO-013
v2.0
Document ownerCyber Security Lead
Version2.0
Approved9 June 2026
Next review9 June 2027
StatusCurrent

Purpose. This procedure sets out how suspected and confirmed cyber security incidents are identified, contained, eradicated, recovered from and reported.

1.Scope

This procedure applies to any event that threatens the confidentiality, integrity or availability of a client or Nova system, including phishing, malware, ransomware, unauthorised access, lost devices and data leakage. It applies to all staff, with the Cyber Security team leading the response.

2.Identification

Alerts from endpoint protection, email security, identity platforms and user reports must be triaged by a security analyst within 30 minutes during business hours and within one hour on call. The analyst must confirm whether an incident has occurred, classify its severity and record it in the Security Incident Register. Evidence such as logs, email headers and screenshots must be preserved before any clean up.

  • Triage within 30 minutes
  • Classify severity from one to four
  • Record in the Security Incident Register
  • Preserve evidence before acting

3.Containment

Containment actions will be chosen to stop the spread with the least disruption, such as isolating the endpoint, disabling the account, revoking sessions, blocking the sender or domain and resetting credentials. Containment for severity one and two incidents must be approved by the Cyber Security Lead and recorded as an emergency change.

4.Eradication and recovery

The root cause must be removed, such as removing malware, closing the vulnerability or removing the mail rule created by the attacker. Systems will be restored from clean backups where required and monitored closely for seven days. The client must be told what was done in plain language.

5.Notification

The client's authorised contact must be notified of every confirmed incident on the day it is confirmed. Where personal information is involved the Business Services Manager must assess whether the notifiable data breaches scheme applies and support the client to notify affected individuals and the Office of the Australian Information Commissioner within the required time.

6.Post incident review

Every severity one and two incident will have a post incident review within ten business days covering timeline, cause, response effectiveness and improvements. Actions will be recorded in the register and tracked to completion.

NOV-PRO-013 v2.0 · CAQA Nova Digital SystemsUncontrolled when printed. Simulated document created by CAQA for training and assessment.