EVIDENCE ARTEFACTS
- Versioned decision record
- Named ownership and approval
- Implementation or test evidence
CONTROL RECORD · REVIEWED 2026-08-30
Make incident triage facts an inspectable system decision with a named owner, defined trigger and retrievable evidence.
Catalogue status
not legal status
IN PLAIN ENGLISH
This practical check helps a team capture the facts it needs, put the right people in the loop, record decisions and later show what happened. It is an engineering aid, not a legal conclusion about a specific incident.
WHO OWNS WHAT
IMPLEMENTATION SEQUENCE
Scope the decision: separate confirmed facts from hypotheses and preserve the decision and communication trail.
Record the approved design and its source-status verification boundary.
Connect implementation events to evidence that a reviewer can retrieve without broad production access.
EVIDENCE ARTEFACTS
CONTROL TEST
Evidence trail (advanced). The remaining sections retain the full implementation steps, failure modes, source pointer, linked pattern and dependency route for engineering and audit review.
ANTI-PATTERNS
ARCHITECTURE → EVIDENCE DECISION JOURNEY
Each connection uses existing catalogue records. Source IDs remain verification pointers—not provision mappings.
Add to a review routeReview SEC-07 before testing this dependent record.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023Separate confirmed facts from hypotheses and generate consistent decision and communication evidence.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, dpdp-rules-2025, act-commencement-2025Trace the sample from its trigger and owner through the implemented system to the retained evidence. Record exceptions, confidence and remediation without converting an unknown into a pass.
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023Named ownership and approval · Implementation or test evidence
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023Marking the control complete from self-attestation alone · Hiding missing, stale or inaccessible evidence behind a pass label
Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023Implementation teams benefit from separating legal interpretation from the engineering artefacts used to execute and test a decision. Radar context: Automated legal-text monitoring is Assess.
Editorial analysis · reviewed 2026-08-30 · sources act-commencement-2025, pib-status-2026Monitor external developments separately from the organisation’s own incident evidence. This route remains optional if the destination is unavailable.
Contextual external property · no affiliation or availability implied| Record | Phase | Relationship | Status / boundary | Source pointers |
|---|---|---|---|---|
| BREACH-01: Incident triage facts | 01 · Prerequisite | Log retention and review Review SEC-07 before testing this dependent record. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 | dpdp-act-2023 |
| BREACH-01: Incident triage facts | 02 · Implementation pattern | Breach fact ledger and communication package Separate confirmed facts from hypotheses and generate consistent decision and communication evidence. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023, dpdp-rules-2025, act-commencement-2025 | dpdp-act-2023 · dpdp-rules-2025 · act-commencement-2025 |
| BREACH-01: Incident triage facts | 03 · Validation / test | Select a recent, in-scope sample for incident triage facts and record why it was chosen. Trace the sample from its trigger and owner through the implemented system to the retained evidence. Record exceptions, confidence and remediation without converting an unknown into a pass. | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 | dpdp-act-2023 |
| BREACH-01: Incident triage facts | 04 · Evidence artefact | Versioned decision record Named ownership and approval · Implementation or test evidence | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 | dpdp-act-2023 |
| BREACH-01: Incident triage facts | 05 · Failure mode | Treating “incident triage facts” as a policy sentence without an operating owner Marking the control complete from self-attestation alone · Hiding missing, stale or inaccessible evidence behind a pass label | Engineering indicator · not a legal requirement · Verification pointers: dpdp-act-2023 | dpdp-act-2023 |
| BREACH-01: Incident triage facts | 06 · Research note | From obligation to evidence: the DPDP implementation stack Implementation teams benefit from separating legal interpretation from the engineering artefacts used to execute and test a decision. Radar context: Automated legal-text monitoring is Assess. | Editorial analysis · reviewed 2026-08-30 · sources act-commencement-2025, pib-status-2026 | act-commencement-2025 · pib-status-2026 |
| BREACH-01: Incident triage facts | 07 · Specialist property | News and discourse signals Monitor external developments separately from the organisation’s own incident evidence. This route remains optional if the destination is unavailable. | Contextual external property · no affiliation or availability implied | None · contextual external route |
GENERIC VERIFICATION POINTER · NOT A PROVISION MAPPING
Provision-specific applicability must be verified against the primary-text ledger.
Boundary: Operational control pattern; not a standalone legal conclusion.
Open the source ledgerCONNECTED SYSTEM PATTERN
Separate confirmed facts from hypotheses and generate consistent decision and communication evidence.
LOCAL WORKSPACE NOTE
Nothing is sent anywhere. Avoid names, personal data or confidential incident details.
CHANGE LOG
Version 1.3 — Architecture-to-evidence journey and non-personal review-route relationship added; verification-pointer boundary retained.
Version 1.2 — Official-source status rechecked; command-centre indexing and the non-mapping boundary retained.
Version 1.1 — Engineering fields, source verification pointers and acceptance evidence reviewed.
Version 1.0 — Stable catalogue ID, objective, evidence model, test sequence and verification boundary established.