Live in Slack or Microsoft Teams

Pull the SOP as it stood on the incident date

An auditor asks which procedure was in force on 14 March. Dash retrieves the version of the SOP that was published on that date, names who approved it, and lists what changed after, so the answer is the record rather than someone's memory.

Get started for free Chat with Dash, the AI teammate that works inside Slack and Microsoft Teams.
9:41
#security-compliance 12 members
Rosa
Rosa
@Dash the auditor wants the incident response SOP as it was on 14 March, not the current one. Can you get that?
Dash
Dash App

Yes. Here is the version that was published and in force on 14 March.

Incident Response Procedure · version 4.2

Published 22 January · superseded 2 April · in force for 71 days, which covers 14 March

Approval record on that version

  • Authored by the security operations lead, 18 January
  • Reviewed by legal, 20 January
  • Approved and published by the head of security, 22 January

What changed after 14 March

  • Version 4.3, 2 April: added the 24 hour customer notification step, which did not exist on 14 March
  • Version 4.4, 19 June: moved severity classification before containment
Worth flagging before you send this. The notification step the auditor is likely asking about was introduced after the incident. Answering from the current SOP would have implied a control that was not in place.
Rosa
Rosa
That is exactly the trap. Can you give me the two versions side by side?
Dash
Dash App

Posted a diff of 4.2 against 4.3 in the thread. Three steps added, one reworded, none removed. Both versions are linked to the stored copy with its own approval trail, so the auditor can open the source rather than take the summary on trust.

I have not sent anything to the auditor. The diff is here for you to check first.

+ Message #security-compliance