Incident Response Runbook
Audience: operators and incident commanders responding to a security or availability incident in a Stella Ops deployment.
This page is an index, not a procedure. It links the operator incident runbooks that carry regulatory-reporting, forensic-evidence, or emergency-access impact. Start here to find the right runbook, then follow that runbook end to end.
Regulatory Reporting
- CRA Article 14 operator reporting: local, offline-first guidance for 24h early warning, 72h vulnerability notification, 14d final report, Evidence Locker incident mode, approvals, fresh-auth, override, and break-glass handling.
Emergency Access And Evidence
Key And Crypto Compromise
- Key Rotation Runbook — see Emergency Key Revocation for compromised-signing-key procedures.
- Key Escrow and Recovery Runbook — see Emergency Procedures for lost or compromised custodian shares.
- Dual-Control Ceremony Runbook — quorum-gated recovery and high-assurance operations.
Notes
Regulator-facing reports must identify the responsible reporting owner before submission. Stella-as-manufacturer incidents and customer-manufacturer incidents use the same evidence tooling, but not the same legal entity or approval chain.
