RB-005 High
AI use detected in restricted department (Legal, HR, Finance)
Detection of AI service access from users in restricted departments (Legal, HR, Finance) via DET-MS-SEN-001 enriched with department data, DET-MS-MCAS-002 user-scope filtering, or DET-NET-001 correlated with identity source.
Triggers
Immediate response (first hours)
- L1 SOC analyst: Verify the user's department against the HR system. Confirm the department is on the restricted list per the AI Acceptable Use Policy.
- L1 SOC analyst: Confirm the restriction policy is current and applies to the detected service. Check for any department-level exceptions or approved pilots.
- L2 SOC analyst: Notify the department manager within 4 hours. Provide factual summary: user identity (pseudonymized in logs), service accessed, timestamp, and applicable policy section. (Within 4 hours of alert)
Short-term response (within days)
- AI Governance triage + Department manager: Interview the user to understand the business context. Determine if a legitimate business need exists and whether sensitive departmental data (attorney-client privilege, employee PII, financial non-public information) was involved. (Within 5 business days)
- AI Governance triage: Assess data exposure. Review DLP events for the user in the detection window. If sensitive data egress is confirmed, escalate to RB-002. (Within 5 business days)
- AI Governance triage: If no data exposure: issue department-appropriate warning using comms/individual-warning-first. If data exposure: coordinate remediation with Privacy/Legal per RB-002. (Within 10 business days)
Long-term response (weeks+)
- AI Governance Committee + Department leadership: Review the department restriction policy. Determine whether the restriction remains appropriate or whether approved alternatives should be evaluated for the department's specific workflows.
- AI Governance triage: If department leadership identifies legitimate use cases: initiate approved-alternative evaluation with enterprise-grade tools that meet the department's regulatory and privilege requirements.
- AI Governance triage: Update detection rules to add department-specific alerting thresholds. Add the department to enhanced monitoring for 90 days.
Decision tree
- Is the user confirmed to be in a restricted department?
- Yes → Proceed with restricted-department response.
- No → Re-route to standard RB-001 process.
- Is the department restriction still current and applicable?
- Yes → Enforce per policy.
- No → Update restriction list; handle as standard RB-001.
- Did the user handle sensitive departmental data (privileged, PII, MNPI)?
- Yes → Escalate to RB-002 for data-exposure response.
- No → Issue warning and monitor.
RACI
- Responsible: L1/L2 SOC analyst
- Accountable: AI Governance triage lead
- Consulted: Department manager, Department head, Legal (for Legal dept incidents), HR Business Partner (for HR dept incidents), CFO office (for Finance dept incidents)
- Informed: AI Governance Committee, CISO
Metrics to capture
- Time from detection to department manager notification (target: ≤ 4 hours)
- Time from notification to user interview (target: ≤ 5 business days)
- Rate of data exposure confirmed in restricted-department cases
- Number of restricted-department cases converting to approved-alternative evaluations
- Repeat rate by department (target: < 5% within 90 days)
Comms templates
comms-manager-talking-pointscomms-individual-warning-firstcomms-department-level-briefing
Framework mappings
- NIST AI RMF: GOVERN-4.1, MANAGE-2.2, MANAGE-4.1
- ISO/IEC 42001: 8.2, 8.4, 10.2
- NIST CSF: RS.AN-1, RS.MI-1, PR.AC-1