Skip to main content
Review and revision metadata
Review Date: 2026-09-02
Reviewer: Operations Manager

previous version on gdrive

Technical Protocol: Emergency Isolations (Emergency Brakes)

This operational guide defines the mandatory sequence for executing an immediate, manual suspension of a compromised or unauthorized user account within the myDRE platform. This "Emergency Brake" protocol serves as a critical containment control under ISO/IEC 27001:2023 (Control A.05.24 - Information Security Incident Management) and NIS 2, halting unauthorized data access or active insider threats without delay.

important

Operational Scope Boundary: This protocol governs emergency, manual tenant-level isolation actions. Automated identity synchronization frameworks (SCIM) are strictly out of scope for this procedure, even when an administrative request specifies an expedited execution track. Insurance Audit Requirement: Prior to invalidating session tokens or executing manual isolation, system log states must be archived and hashed to maintain audit compliance (Right to Inspection).

Forensic & Insurer Evidence Preservation Notice​

Prior to executing permanent identity de-provisioning, password rollbacks, or resource purging during an active security anomaly:

  • Export and cryptographically hash all relevant Entra ID sign-in logs, audit entries, and session tokens.

  • Ensure all actions are timestamped and appended to the incident ticket to satisfy Chubb's evidence preservation requirement.

  • Emergency Breaks