When something happens · 4.2

Reporting obligations and their clocks

Reporting obligations and their clocks. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see FIRST CSIRT Services Framework.

The number everybody knows

Seventy-two hours, and what it runs from

The defence clause requires rapid reporting within seventy-two hours of discovery. Two words in that sentence do work.

Discovery, not occurrence. The clock starts when you find out, which is frequently long after the event and is why the detection question matters commercially as well as technically.

Rapid is the standard; the seventy-two hours is the outer limit rather than the target.

Rests on

The safeguarding clause in the defence acquisition regulation supplement, which states the reporting timeframe and the preservation requirement, and the reporting portal it directs reports to.

The clause text is published and should be read in the version incorporated into your own contract.

The practical obstacle

You cannot report without a certificate

Submitting a report requires an approved medium assurance certificate. Obtaining one takes time, involves an external authority, and cannot be done during an incident.

This is the single most common way a supplier misses the deadline: not because they did not know about it, but because at hour six they discovered the submission required something they did not have.

Obtain it now, while nothing is happening, and check annually that it has not expired.

Preservation

The other obligation in the same clause

Images and monitoring data covering the affected systems must be preserved for a period after the report, so that the government can request them.

Which means the instinct to rebuild the machine and get back to work is the instinct that destroys the thing you are required to keep. The entry on the first hour treats this properly.

The other clocks

Four more, running at the same time

Your customer's clause. A prime may require notification faster than the government does, and their clause is in your contract with them.

Data protection law. If personal data is involved, separate regimes with their own deadlines may apply, and in some jurisdictions those are also measured in hours.

Your insurer. Cyber policies commonly require prompt notification and can decline cover for late notice.

Any sector obligation you carry for other reasons.

These are not alternatives to each other. Work out which apply to you before you need to, and keep the list with the incident plan.

What to have ready

Six things, prepared in advance

The certificate. The list of clocks above. The template with the fields the report requires. The named person and deputy. The contact details for legal advice out of hours. And the paper copy, because a plan stored only on the affected network is not a plan.

Practising the clock

Time a tabletop exercise

Run a scenario and measure how long it takes to reach a reporting decision and assemble the information the report needs. Most organisations doing this for the first time exceed the deadline in the exercise, which is the cheapest possible place to discover it.

Not advice

The clocks that apply to you

Which obligations you carry depends on your contracts, your jurisdictions and the nature of the data. This entry describes the shape of the problem and nothing in it is legal advice; establish your own list with counsel and keep it current.

Also

Elsewhere in when something happens