Download presentation
Presentation is loading. Please wait.
Published byGavin Bryant Modified over 6 years ago
1
Jane Drews University IT Security Officer EDUCAUSE On-line 2009
Incident Management Jane Drews University IT Security Officer EDUCAUSE On-line 2009
2
General Elements Policy Training Technical and operational issues
Procedures and decision making Quality Improvement
3
EDUCAUSE/I2 Information Security Guide
Aligns with ISO standards for Information Security Management Chapter 13: Information Security Incident Management
4
Sample Security Incident
Some policy was in place Decision making authority and depth Technical decisions Political decisions Operational decisions Insufficient security services Notification questions not fully understood
5
Notification Considerations
Applicable policy, and/or local, state, or federal laws Physical possession (lost or stolen device?) Credible evidence the information was copied/removed Length of time between intrusion and detection Purpose of the intrusion was acquisition of information Credible evidence the information was in a useable format (unencrypted) Ability to reach the affected individuals
6
Preparation, Detection, and Reporting
Policy for reporting, containment, notifications, communications Training – End users, IT admins, and Security personnel Technical resources/services Detection, analysis, forensics
7
Security Incident Response and Process Improvement
Response team members vary by incident Security, Sysadmins Affected Unit, Legal, LE, Media/Relations, Administration, CIO, CISO Clearly defined expectations at all levels Responsibility, timing, recovery Debriefing (lessons learned)
8
Questions ?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.