This document is under active development and has not been finalised.
Skip to content

5.4 Communication Plan

Overview

The communication plan defines the internal and external communication channels for security incidents. The objective is rapid, consistent and legally compliant information sharing.

Communication Matrix

Internal Communication

SeverityRecipientsChannelTimeframe
SEV-1Security Lead, DevOps Lead, Management, Dev TeamTeams (Incident Channel) + PhoneImmediately
SEV-2Security Lead, DevOps Lead, affected Dev TeamTeams (Incident Channel)≤ 1 hour
SEV-3Security Lead, affected Dev TeamTeams + GitHub Issue≤ 4 hours
SEV-4Affected Dev TeamGitHub Issue≤ 24 hours

External Communication

RecipientChannelTimeframeResponsible
ENISA / CSIRTSingle Reporting Platform≤ 24h (early warning)Security Lead
Affected usersGitHub Advisory + EmailWithout delay (after fix)Security Lead + Product Owner
PublicGitHub Security AdvisoryAfter patch availabilitySecurity Lead
Security researchers (CVD)GitHub Advisory / EmailPer Disclosure PolicySecurity Lead

Communication Templates

Internal Initial Notification (Teams)

🚨 SECURITY INCIDENT – SEV-[1/2/3/4]

Product: [Product name] v[Version]
Vulnerability: [CVE-ID or brief description]
Severity: [CRITICAL/HIGH/MEDIUM/LOW]
Actively exploited: [Yes/No/Unknown]
ENISA reportable: [Yes/No]

Status: [Triage/Containment/Remediation/Closed]
Next steps: [Description]
Responsible: [Name]

Incident ticket: [Link to GitHub Issue]

External User Notification

Security Notice – [Product name]

Dear user,

we have identified and remediated a security vulnerability
in [Product name].

Affected versions: [Versions]
Fixed version: [Version]
Severity: [CRITICAL/HIGH]
CVE: [CVE-ID]

Recommended action:
Please update to version [X.Y.Z].

Details: [Link to Security Advisory]

For questions, please contact: disclosure@cra.docs.bauer-group.com

Escalation Paths

SEV-1 (Critical):
Developer → Security Lead → Management → ENISA (24h)
                                       → Users (without delay)

SEV-2 (High):
Developer → Security Lead → Management (info)
                          → Users (after fix)

SEV-3 (Medium):
Developer → Security Lead → Patch in next release

SEV-4 (Low):
Developer → Backlog → Regular release

Teams Integration

The existing Teams notification (teams-notifications.yml) is extended for security incidents:

  • Incident Channel: Dedicated Teams channel for security incidents
  • Automatic Alerts: For CRITICAL/HIGH CVE findings from the CVE monitor
  • Status Updates: Automatic updates on status changes of the incident ticket

Documentation Requirement

All communication in the context of a security incident is documented:

  • Timestamp of each communication
  • Recipient and channel
  • Content (summary)
  • Confirmation of receipt

This documentation is part of the incident ticket and serves as evidence vis-a-vis supervisory authorities.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT