Archer Australian Incident Management

The Archer Australian Incident Management Accelerator is a streamlined version of the Archer Incident Management use case specific to customers in Australia. This offering allows customers to quickly and easily document, triage and remediate compliance and risk incidents. It provides a simplified workflow to create incidents, conduct compliance reviews, assign ownership, investigate, and close incidents.

Archer Exchange: With the Archer Exchange, the Archer team and our trusted partners have created a broad selection of supplemental, value-added offerings to help you get your unique risk management program on the right path, right from the start. You can leverage the Archer Exchange offerings to expand the use of Archer solutions into new business processes and address specific industry, geographic, regulatory, or technical requirements. The Archer Exchange features a fast and agile development cycle, enabling quick delivery of new and updated offerings for trending issues and connections to innovative technologies.

Release notes

Last updated: August 2023

Overview

Organizations develop comprehensive incident response plans that outline the roles and responsibilities of team members, communication protocols, escalation procedures, and the steps to be taken during different types of incidents. These plans are tailored to the specific needs of the organization and its industry. The incident management process begins with identifying and classifying incidents. Once an incident is identified, it is escalated to the appropriate personnel or teams within the organization. This often includes notifying various stakeholders within the organization and often times the governing regulatory bodies.

Archer Australian Incident Management Accelerator provides case management and incident response for reporting and categorizing cyber and physical incidents and determining the appropriate response procedures.

Archer Australian Incident Management Accelerator provides a streamlined version of the Archer Incident Management use case that supports specific requirements for managing incidents in Australia, such as ASIC’s RG78, OAIC, and Corporations Act s912D Checklists. It provides a metrics dashboard for tracking and reporting the status of all incidents, their costs, related incidents, losses and recovery.

The Archer Australian Incident Management Accelerator can be paired with Archer Australian Regulatory Correspondence to facilitate regulatory reporting. Organizations are required to report to regulators to ensure compliance with industry laws, mitigate risks, and demonstrate transparency in their operations. This includes reporting on operational disruptions, cybersecurity incidents, compliance breaches, and other regulatory obligations specific to their industry. By leveraging these solutions, clients can streamline reporting processes, ensure timely submissions, and maintain accurate records to meet regulatory requirements efficiently.

Features and benefits

The Archer Australian Incident Management Accelerator offering enables organizations todo the following tasks.

  • Support the documentation, triage and remediation of compliance and risk incidents.

  • Include a simplified workflow allowing the creation, compliance review, ownership and closure of incidents.

  • Track due dates in line with regulatory reporting timeframes.

  • Track correspondence sent to and received from regulators.

  • Support the process to investigate into serious or likely breach.

  • Use built-in checklists to prompt the assessment of whether an incident could be any of the following items.

    • Breach per Corporations Act 2001 s912D.

    • Reportable situation per Regulatory Guide 78 Breach reporting by AFS licensees and credit licensees (RG 78).

    • Notifiable data breach per Office of the Australian Information Commissions (OAIC).

The Archer Australian Incident Management Accelerator has the following benefits.

  • Solution tailored specificall for Australian clients' unique requirements.

  • Centralized simplified incident workflow and tracking.

  • Customizable incident response plans to address your organization's specific challenges.

User Guide

Administrator guide

Prerequisites (System requirements)

Components

Prerequisites

Archer Solution Area(s)

Archer Resilience Management

Archer Use Case(s)

  • Archer Incident Management

  • Archer Issues Management

Archer Applications

  • Incidents

  • Investigations

  • Australian Regulatory Correspondence (Optional)

Uses Custom Objects

No

Requires Archer On-Demand Application Licenses

Zero (0) Archer On-Demand Application licenses required.

Archer Licensing Requires Archer Australian Regulatory Correspondence license for use of the Australian Regulatory Correspondence application.

Archer Requirements

Archer Platform Release 6.13 and later

Supported Archer Environments
  • On-Premises

  • SaaS

Compatible use cases and applications - related applications

Application

Use Case

Primary Purpose(s) of the Relationship

FAR Regulatory Correspondence

Individual Accountability Management

  • You can tie your regulatory correspondence to the investigations.

Contacts

Business Asset Catalog

  • To identify the Representative on the Incident

Business Unit

 

Business Asset Catalog

  • To relate Business Units to the Incident for the Business Unit Impacted and/or the Business Unit where the Incident Occurred.

Division

 

Business Asset Catalog

  • To relate Division to the Incident for the Division Impacted and/or the Division where the Incident Occurred.

Products and Services

Business Asset Catalog

  • To relate Products and Services that are impacted by the Incident.

Facilities

Business Asset Catalog

  • To relate Facilities that are related to the Investigations.

Components

Architecture diagram

A diagram of a process  Description automatically generated

Process diagrams

Incidents

A diagram of a flowchart  Description automatically generated

Investigations

A diagram of a company  Description automatically generated

Applications

Application

Description

Incidents

The Incidents application provides a central repository for reporting incidents and managing the incident lifecycle. Through the Incidents application

Investigations

The Investigations application allows you to report and manage investigations for one or more incidents.

FAR Regulatory Correspondence

The FAR Regulatory Correspondence application provides the ability to track regulatory communication and track submission of such to the Regulator.

Personas and access roles

The following table describes the functions that make up the application’s organization roles. Depending on the organization of your company, these functions and responsibilities may vary.

Function

Description

Compliance Manager

The Compliance Manager is the initial point of contact for intaking and triaging Incidents. The Compliance Manager is responsible for conducting the Impact Assessments, any Breach evaluations and assigning the Incident Owner. Furthermore, the Compliance Manager reviews the Incident once it’s been submitted by the Incident Owner for closure.

Incident Owner

The Incident Owner is the individual within the Business who owns the overarching Remediation of the Incident. The Incident Owner is also able to track details around Financial Loss.

Incidents Legal Team

The Incident Legal Team is a Group which can be leveraged to notify the Legal department where there might be a breach that requires Legal oversight. The Legal Team isn’t a formal part of the workflow, however they are notified when required as a result of Breach determination by the Compliance Manager.

Permissions chart

Applications

IM: Admin

IM: Owner

CM: Manager

RM: Manager

Incidents: Legal

Incidents: General User

Incidents

CRUD

CRU

CRU

CRU

R

CRU

Investigations

CRUD

CRU

CRU

CRU

R

 

FAR Regulatory Correspondence

CRUD

CRU

CRU

CRU

R

 

Remediation Plans

CRU

CRU

CRU

R

R

 

Business Unit

RU

RU

RU

R

R

 

Division

RU

RU

RU

R

R

 

Contacts

RU

RU

RU

R

R

 

Products and Services

RU

RU

RU

R

R

 

Facilities

RU

RU

RU

R

R

 

C = Create, R = Read, U = Update, D = Delete

Install Archer Australian Incident Management Accelerator

  1. Prepare for the installation.

  2. Install the package.

  3. (Optional) Set up the data feeds.

  4. Test the offering according to your company standards and procedures, to ensure that it works with your existing processes.

Prepare for the installation

  1. Ensure that your Archer system is at Archer Platform version 6.13 or later.

  2. Download the installation package.

  3. Read and understand "Packaging Data" in the Archer Platform Help.

Install the package

Set up data feeds (optional)

If you are using or installed the FAR Regulatory Correspondence application, then configure the below data feed.

Certification environment

Date tested: August 2023

Product Name

Version Information

Operating System

Archer

6.13

Virtual Appliance