Investigate data incidents#
This task is the responsibility of Trusted Research Environments Service Area (TRESA).
If there is any suspicion of a data incident such as:
unauthorised data ingress or egress
unauthorised access
users breaking the terms-of-use
then an incident report meeting will be held as soon as possible.
The following people should be invited to this meeting:
Turing data protection representative
Trusted Research Environments Service Area (TRESA) administrator contact
project PI
project referee
During the meeting a decision should be made about what action needs to be taken. This may involve, for example:
shutdown of a TRE
suspension of a user from the TRE (permanently or temporary)
removal of data from a TRE
A report of the incident should be written up and stored for the Turing’s records:
Report data incidents#
Navigate to Sharepoint and
information_governance
->incident reports
Make a copy of
YYYY-MM-DD_report_template.tex
template to write a report and give it an appropriate nameWrite up your report of the incident using the template’s suggested headers, but feel free to add as much or as little information as is required for the particular incident
Convert the report to PDF using the
make_pdf.sh
scriptShare with everyone who was invited to the incident meeting for comment (see above)
Edit the report as needed and ensure the final PDF is saved in the
incident reports
folder