Table of Contents
- 1. Purpose
- 2. Scope
- 3. Policy Statement
- 4. Roles and Responsibilities
- 5. Policy Requirements
- 6. Implementation Guidance
- 7. Monitoring, Evidence, and Compliance
- 8. Exceptions
- 9. Review and Maintenance
- 10. Related Standards
1. Purpose
Ligala Tech Pte operates legal technology services that process sensitive client information, employee data, and cloud-hosted business records. This policy establishes a structured and auditable approach for identifying, triaging, containing, investigating, and recovering from security and privacy incidents that may affect the confidentiality, integrity, or availability of those services. It is designed to reduce the likelihood that incidents escalate into reportable personal data breaches, prolonged service outages, or unauthorized access to customer and company systems.
This policy supports Ligala Tech Pte’s obligations under Singapore’s Personal Data Protection Act (PDPA), including timely assessment and notification of notifiable data breaches, and aligns the organization’s incident management practices with ISO 27001 expectations for security event and incident handling. Because Ligala Tech Pte is a small organization, its incident response model must be practical, repeatable, and clearly assigned to named owners rather than relying on informal or ad hoc responses.
A specific objective of this policy is to address the open high-severity finding involving the AWS Reserved SSO AdministratorAccess role with excessive privileges. The policy requires that overly permissive access be identified, contained, reduced, and monitored so that misuse of administrative privileges does not lead to unauthorized access, accidental deletion, data exposure, or prolonged business interruption.
2. Scope
This policy applies to all Ligala Tech Pte employees, contractors, interns, temporary personnel, and third parties who create, access, administer, support, or process company information or systems. It covers incidents affecting cloud infrastructure, identity and access management, endpoints, application services, repositories, logging systems, customer data, and any operational tooling used to deliver legal technology services. It applies regardless of whether the incident is confirmed, suspected, internal, external, accidental, or malicious.
The policy includes incidents involving employee actions, cloud identities, privileged access, compromised accounts, phishing, malware, configuration errors, data leakage, unauthorized data disclosure, service disruptions, and loss of availability in the cloud environment. It also applies to security events that may become incidents if evidence indicates impact or credible risk, such as suspicious login activity, abnormal privilege elevation, or unexpected changes to production resources. Because Ligala Tech Pte stores and processes personal data and client-related information, privacy incidents are in scope even if no system outage occurs.
This policy also extends to the investigation and remediation of known control weaknesses that can reasonably lead to incidents, including excessive AWS administrative permissions. The organization may use this policy to drive corrective actions even before an incident occurs when a significant exposure creates an unacceptable risk. Where a third-party service is involved, Ligala Tech Pte remains responsible for ensuring that response coordination, evidence preservation, and notification obligations are met.
3. Policy Statement
Ligala Tech Pte shall maintain a documented incident management capability that enables the company to detect, classify, contain, investigate, and recover from security and privacy incidents in a timely and proportionate manner. All personnel must promptly report suspected incidents and must not attempt to conceal, delay, or independently resolve serious events without involving designated response owners. The response process must prioritize preservation of evidence, rapid containment, clear decision-making, and accurate communication.
For privacy incidents, Ligala Tech Pte shall determine whether a breach is notifiable under Singapore PDPA requirements and shall support prompt internal escalation and external notification when thresholds are met. For security incidents, the company shall evaluate business impact, sensitivity of affected data, affected systems, and the likelihood of unauthorized access or disruption. Incident handling must be consistent, documented, and supported by logs, ticket records, and corrective action tracking.
Ligala Tech Pte shall actively reduce known high-risk conditions that increase incident likelihood or impact. This includes reviewing privileged cloud roles, implementing least privilege, and restricting administrative access to approved personnel only. The AWSReservedSSO_AdministratorAccess finding shall be treated as a control deficiency requiring remediation, monitoring, and verification until resolved, because excessive privileges can bypass normal safeguards and materially increase the risk of unauthorized access or service disruption.
4. Roles and Responsibilities
- Managing Director: Has ultimate accountability for approving this policy, ensuring resources are available for incident response, and deciding on major business-impacting actions such as emergency service suspension, client communications, or external legal engagement.
- Security and Privacy Incident Owner: Coordinates the incident response process, performs initial triage, maintains the incident log, ensures escalation thresholds are applied, and oversees containment, investigation, and recovery activities.
- Cloud Administrator: Implements technical containment and remediation actions in AWS and related cloud services, including privilege reduction, access revocation, log preservation, and configuration hardening.
- System/Application Owner: Provides service-specific knowledge, supports impact assessment and recovery actions, validates whether customer-facing services or data stores were affected, and confirms restoration of normal operations.
- Data Protection Officer or Privacy Lead: Assesses personal data exposure, determines PDPA notification obligations, coordinates privacy impact analysis, and supports customer or regulator communications when required.
- All Employees and Contractors: Must immediately report suspected incidents, follow instructions from the incident response lead, protect evidence, and avoid unauthorized disclosure or interference with affected systems.
- External Service Providers: Must notify Ligala Tech Pte promptly upon detecting relevant incidents, cooperate with containment and investigation, preserve logs and evidence, and support service restoration according to contractual obligations.
5. Policy Requirements
- All personnel must report suspected security or privacy incidents to the Security and Privacy Incident Owner within 1 hour of discovery. Owner: All employees and contractors. Frequency: Every suspected incident. Evidence: Incident ticket, chat or email notification timestamp, and acknowledgment record.
- The Security and Privacy Incident Owner must triage each reported event and assign a severity level within 4 business hours for low-risk events and within 1 hour for high-risk events. Owner: Security and Privacy Incident Owner. Frequency: Each incident. Evidence: Triage record showing severity, rationale, and timestamp.
- The Cloud Administrator must immediately disable, restrict, or compensate for any compromised or excessively privileged account when there is credible risk of misuse. Owner: Cloud Administrator. Frequency: Upon detection of compromised or excessive privilege conditions. Evidence: IAM change record, access review note, and before/after policy snapshot.
- Ligala Tech Pte must enforce least privilege for AWS and other cloud identities, and the AdministratorAccess policy must not remain assigned to standing day-to-day operational roles unless explicitly justified and approved. Owner: Cloud Administrator with approval from Managing Director. Frequency: Review monthly and upon role creation or change. Evidence: IAM access review report, approved exception or remediation ticket.
- The Security and Privacy Incident Owner must preserve logs, snapshots, alerts, and relevant communications before any destructive remediation whenever practical. Owner: Security and Privacy Incident Owner with Cloud Administrator support. Frequency: Every incident. Evidence: Evidence preservation checklist, exported logs, and storage location record.
- The Data Protection Officer or Privacy Lead must evaluate all incidents involving personal data for PDPA notification obligations within 24 hours of credible confirmation. Owner: Data Protection Officer or Privacy Lead. Frequency: Every privacy incident. Evidence: Assessment memo, decision log, and notification determination.
- The System/Application Owner must validate service restoration and data integrity before returning affected services to normal operation. Owner: System/Application Owner. Frequency: Every recovery event. Evidence: Recovery verification checklist, test results, and sign-off record.
- Root cause analysis must be completed for high-severity incidents within 5 business days and for all other incidents within 10 business days. Owner: Security and Privacy Incident Owner. Frequency: Each incident requiring formal review. Evidence: Post-incident report, corrective actions, and management review notes.
- Corrective actions from incidents must be tracked to closure with named owners and due dates. Owner: Security and Privacy Incident Owner. Frequency: Weekly until closure. Evidence: Action tracker, status updates, and closure verification.
- Employees with incident handling responsibilities must receive annual training on incident reporting, evidence handling, and PDPA breach escalation. Owner: Managing Director supported by Security and Privacy Incident Owner. Frequency: Annually. Evidence: Training records, attendance logs, and training materials.
- Tabletop or simulation exercises covering security and privacy incidents must be performed at least twice per year, including one scenario involving privileged cloud access misuse or AWS account compromise. Owner: Security and Privacy Incident Owner. Frequency: Semiannually. Evidence: Exercise plan, attendance, findings, and improvement actions.
- Backups, logging, and monitoring controls supporting incident detection and recovery must be checked for integrity and availability at least monthly. Owner: Cloud Administrator. Frequency: Monthly. Evidence: Monitoring report, backup verification record, and alert test results.
- Any incident communication to customers, regulators, or partners must be approved by the Managing Director and the Data Protection Officer or Privacy Lead before release. Owner: Managing Director and Data Protection Officer or Privacy Lead. Frequency: Per communication event. Evidence: Approved communication draft, approval record, and distribution log.
6. Implementation Guidance
Ligala Tech Pte should implement this policy through a simple but disciplined incident response workflow that fits the company’s size. The workflow should begin with a single reporting channel, such as a dedicated email alias and messaging group monitored by the Security and Privacy Incident Owner. Reports should be acknowledged quickly, assigned a case number, and categorized using a severity model that considers data sensitivity, operational impact, exploitability, and legal exposure. A lightweight incident log should capture time of discovery, reporter, affected assets, preliminary assessment, and decisions made.
Operational readiness should focus on a small set of high-value controls. Centralized logging in AWS, identity provider audit logs, endpoint security telemetry, and alerting for privilege changes are especially important. The organization should prioritize remediation of the AdministratorAccess exposure by replacing standing broad privileges with role-based access, separate admin and non-admin accounts, just-in-time elevation where practical, and approval-based access changes. Where full automation is not yet feasible, manual compensating controls should be documented and time-bound.
Recovery planning should be realistic for a 1-10 person company. Ligala Tech Pte should define essential systems, recovery order, minimum staffing for incident handling, and communication templates in advance. The company should also maintain runbooks for common scenarios such as phishing, account compromise, accidental data sharing, ransomware, and cloud misconfiguration. Tabletop exercises should validate that personnel know how to escalate, preserve evidence, and restore services while minimizing additional harm. Findings from exercises and real incidents should directly update controls, runbooks, and training.
7. Monitoring, Evidence, and Compliance
Ligala Tech Pte shall monitor incident-related activity through security alerts, IAM change logs, authentication logs, cloud provider audit trails, and service availability monitoring. The Security and Privacy Incident Owner shall review open incidents weekly until closure and shall escalate overdue actions, unresolved high-severity issues, or repeated control failures to the Managing Director. If an incident suggests a reportable personal data breach, the Privacy Lead must be informed immediately so that PDPA assessment timelines are met.
Evidence must be retained in a manner that supports both operational learning and regulatory defense. Minimum artifacts include incident tickets, timestamps, logs, screenshots, exported audit records, root cause analyses, recovery checklists, approval records, training attendance, exercise reports, exception approvals, and remediation evidence for privilege reduction. Evidence should be stored in an access-controlled repository with integrity protections and retained according to the company’s record retention and legal hold practices.
Compliance is measured through timely reporting, severity assignment, completion of containment and recovery steps, closure of corrective actions, and successful reduction of known exposure areas such as excessive privileges. Escalation is required when reporting deadlines are missed, when a high-severity incident cannot be contained promptly, when personal data may have been accessed without authorization, when privileged credentials are suspected to be compromised, or when a control deficiency persists beyond its remediation due date. Repeated non-compliance may result in access restrictions, disciplinary action, or vendor review.
8. Exceptions
Exceptions to this policy may be granted only when a business need cannot be met through standard controls and when the residual risk is understood and accepted. Requests must be documented, state the control being excepted, identify compensating controls, define the duration, and include the reason the standard requirement cannot be met. The Security and Privacy Incident Owner must review the request, and approval must be obtained from the Managing Director; privacy-related exceptions also require review by the Data Protection Officer or Privacy Lead.
All exceptions must include an expiry date and a remediation plan. Exceptions related to privileged access, incident response delays, or evidence handling should be rare and narrowly scoped. Temporary access elevations or emergency access arrangements must be time-boxed and reviewed after use to confirm they were appropriate. Expired exceptions are invalid unless explicitly renewed through the same approval process.
9. Review and Maintenance
This policy must be reviewed at least annually and after any major incident, significant change in the cloud environment, new legal obligation, or repeated control failure. The Security and Privacy Incident Owner is responsible for initiating the review, and the Managing Director must approve material revisions. If a review reveals a gap in incident handling, the policy should be updated promptly rather than waiting for the annual cycle.
Supporting procedures, runbooks, contact lists, and communication templates must be maintained in parallel with this policy so the organization can execute the response process without delay. Changes to roles, cloud architecture, logging tools, or regulated data processing should trigger an out-of-cycle review of relevant incident response procedures. Obsolete versions must be archived and retained for auditability, while active versions must remain accessible to personnel with incident response duties.
10. Related Standards
Singapore PDPA connects directly to this policy because Ligala Tech Pte processes personal data and must assess whether a breach is notifiable, mitigate harm, and notify affected parties and the Personal Data Protection Commission when required. This policy operationalizes those obligations by requiring rapid reporting, privacy impact assessment, evidence preservation, and approved external communications.
ISO 27001 connects to this policy through its requirements for security event identification, incident management, root cause analysis, corrective action, and continual improvement. The policy translates those expectations into practical controls for a small legal technology company, including assigned roles, documented response steps, periodic exercises, and retention of evidence. The AWS privilege finding is also addressed through the ISO principle of access control and risk treatment, ensuring that known weaknesses are reduced rather than accepted without review.
Together, these standards shape a response model that protects client trust, supports legal and regulatory defensibility, and strengthens the resilience of Ligala Tech Pte’s cloud-based services.
Comments
0 comments
Please sign in to leave a comment.