Security & Compliance
Incident Response Policy
How Skoolfly detects, contains, investigates and recovers from security incidents.
1. Policy Statement
Skoolfly maintains a structured approach to detecting, reporting, containing, investigating and recovering from security incidents. This policy defines incident types, severity levels, roles and response steps to minimise impact and prevent recurrence.
2. Purpose
The purpose of this policy is to enable a timely, coordinated response that protects data, systems and users, meets legal and contractual obligations, and improves security from lessons learned.
3. Scope
This policy applies to all security incidents affecting Skoolfly systems, data, personnel or third parties, including suspected or confirmed events involving personal data, accounts, infrastructure, applications, networks or physical security.
4. Definitions and Incident Types
Security incident: an event that jeopardises the confidentiality, integrity or availability of information or systems.
Personal data breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Account compromise: unauthorised access to a user or administrative account.
Malware or ransomware: infection of systems by malicious software.
Denial of service: disruption of availability through excessive traffic or abuse.
Misconfiguration or data exposure: accidental exposure of data or systems.
Insider misuse: inappropriate or unauthorised activity by personnel.
5. Incident Severity Levels
6. Roles and Responsibilities
7. Detection and Reporting
Suspected incidents are reported without delay, with as much detail as is known.
Users are expected to report anomalies rather than investigate alone.
Monitoring, alerts and user reports feed a single incident intake process.
No person is penalised for promptly reporting a suspected incident in good faith.
8. Response Phases
Responses follow a defined set of phases, applied proportionately to the severity of the incident.
Preparation: roles, tools and procedures are maintained and tested before incidents occur.
Identification: the incident is confirmed, scoped and classified.
Containment: immediate steps limit further damage or exposure.
Eradication: the cause is removed and affected systems secured.
Recovery: services are restored and verified to be working correctly.
Lessons learned: findings are reviewed and improvements implemented.
9. Communication and Disclosure
Communication about incidents is coordinated to ensure accuracy and consistency. Schools, users, clients and the public are informed where appropriate, in accordance with contractual and legal requirements, without providing information prematurely that could aid attackers or compromise the investigation.
10. Legal and Regulatory Notification
Where required, incidents are notified to regulators and affected individuals within applicable timeframes, in line with the Data Protection & Privacy Policy and applicable law. Notification decisions are documented.
11. Documentation
Significant incidents are documented, including timeline, root cause, impact, actions taken and preventive measures. Documentation is retained in accordance with the Data Retention Policy and treated as confidential.
12. Review
This policy is reviewed at least annually, after significant incidents, and when response tools, systems or obligations change materially.
