Technical Protocol: Emergency Isolations (Emergency Brakes)
This operational guide defines the mandatory sequence for executing an immediate, manual suspension of a compromised or unauthorized user account within the myDRE platform. This "Emergency Brake" protocol serves as a critical containment control under ISO/IEC 27001:2023 (Control A.05.24 - Information Security Incident Management) and NIS 2, halting unauthorized data access or active insider threats without delay.
Operational Scope Boundary: This protocol governs emergency, manual tenant-level isolation actions. Automated identity synchronization frameworks (SCIM) are strictly out of scope for this procedure, even when an administrative request specifies an expedited execution track. Insurance Audit Requirement: Prior to invalidating session tokens or executing manual isolation, system log states must be archived and hashed to maintain audit compliance (Right to Inspection).
Forensic & Insurer Evidence Preservation Notice
Prior to executing permanent identity de-provisioning, password rollbacks, or resource purging during an active security anomaly:
-
Export and cryptographically hash all relevant Entra ID sign-in logs, audit entries, and session tokens.
-
Ensure all actions are timestamped and appended to the incident ticket to satisfy Chubb's evidence preservation requirement.
- Emergency Breaks