Operating model
NRDEX should be run as a continuously monitored national platform with clear accountability for availability, performance, and incident response.
Monitoring areas
- Core platform uptime
- Service latency
- Failed requests
- Certificate health
- Queue or throughput pressure
- Unusual access patterns
Logging requirements
- Log service requests and responses at the required metadata level
- Protect logs against unauthorized modification
- Retain logs according to policy and legal requirements
- Make logs available for audit and incident investigation
Log documentation references
Implementation teams should use the X-Road documentation as the technical reference for Security Server logs and monitoring behavior:
- Security Server User Guide for message log, audit log, service configuration, and administrative operations
- Operational Monitoring Protocol for operational metrics exposed by Security Servers
- Security hardening guide for host-level controls that protect logs and administrative access
- NRDEX (X-Road official) documentation links for the maintained local reference list
Incident response
- Detect and classify the event
- Contain affected services or access paths
- Notify relevant institutional stakeholders
- Recover service safely
- Record findings and corrective actions
Availability expectations
- Define target uptime objectives
- Schedule and publish maintenance windows
- Test backup and recovery procedures
- Review recurring failure patterns with participating institutions
Support model
Each participating institution should maintain both a business contact and a technical contact for production coordination, incident handling, and change notification.