This is the full text published in the Phase 7 package. Effective dates, responsible contacts and contract-specific parameters are maintained in the corresponding release and deployment records.
Signals and intake
Signals may come from alerts, users, suppliers, anomalous matching, key compromise or data exposure. Intake creates an incident reference with discovery time, systems, symptoms and reporter. Unknown causes do not prevent intake or escalation while a full technical report is pending.
Classification and coordination
Assess impact on identity, data, availability, devices and service entitlement. Assign an incident coordinator and communications channel under the contractual model. Customer, Mobile-ID and supplier responsibilities remain distinct; a supplier-originated incident does not remove the responsible party's tracking duty.
Containment and safe continuity
Authorized containment may suspend devices, accounts, tokens, connectivity or biometric bindings. Preserve evidence during containment. Essential services, including healthcare, switch to approved alternatives rather than automatically granting all access or blocking every user because palm processing is impaired.
Preservation and investigation
Preserve logs, configuration versions, authorization events and enough evidence references for investigation. Record collector, time, source and handovers. Hashes support file-integrity checks, not every investigative conclusion. Bulk raw-biometric exports require an explicit purpose and authority.
Notifications and obligations
Legal and service owners determine recipients, content, deadlines and authorities for the specific event. This draft invents no 24/72-hour rule. Outgoing updates distinguish established facts, open investigation and next steps; they do not promise an unsupported recovery time.
Recovery and re-entry criteria
The recovery plan records clean sources, versions, key/certificate checks, integrity and revocation/deletion synchronization. Before re-entry, test business flows, denials, access and alternatives. An authorized owner approves reopening; the absence of an alert does not itself establish safety.
Closure and lessons learned
Closure documents the timeline, impact, decisions, communications, remaining limitations and prevention actions. Each action has an accountable person and approved checkpoint. Findings affecting policy, firmware, SDKs or data enter change management and regression testing.
Exercises and coordination
Exercises cover loss of identity-source connectivity, revoked devices, leaked tokens, outdated backups and wrong-person binding. Use synthetic data in an authorized environment. Frequency, depth and participants are operational approval items; exercise results are not real incident reports.
Responsibility & deployment annex
Detailed responsibilities are determined by activity and deployment records; this public document does not replace customer-specific contractual annexes.
- The relying organization defines business purposes, populations and operational authority within the deployment.
- Mobile-ID supplies and operates components within the agreed scope, including integration, control configuration and related evidence.
- Device suppliers support models, firmware, SDKs and maintenance within authorization; data access is never implicit.
- Legal, security and service ownership assignments are maintained in each organization’s operating records.
Execution and evidence cycle
- Record purpose, organization, data/device scope and the business reference.
- Verify authority, applicable conditions, configuration and relevant obligations.
- Execute with data minimization, authorization and necessary evidence.
- Close with confirmations from relevant systems, response handling and remaining exceptions.
Legal and reference sources
Detailed obligations, periods and exceptions apply according to law, contract and the actual service configuration.