Transcription of Information Security Incident Management Procedures
{{id}} {{{paragraph}}}
Information Security Incident Management Procedures September 2013 HERIOT-WATT UNIVERSITY Procedures TO SUPPORT Information Security Incident Management POLICY CONTENTS Section Page 1 Introduction 3 2 How to report an Information Security Incident 3 3 How to manage the response to an Incident 4 Who needs to be involved? 5 Assessing the risks and actions to be taken 5 Who else needs to be informed? 5 Reviewing the Incident 6 4 Monitoring and managing risks 7 5 Related policies, Procedures and further reference 7 6 Further help and advice 7 7 Definitions 8 8 Procedure version and history 9 Appendix 1 Information Security Incident report 10 Appendix 2 Information Security Incident Management checklist 11 Appendix 3 Information Security Incident escalation process 19 Appendix 4 Information Security Incident response flowchart 20 Heriot-Watt University Information Security Incident Management Procedures Version 2: August 2013 Author: Ann Jones URL 3 1.
The Information Security Officer and the Director of Governance and Legal Services will identify any significant risks that need to be escalated as a matter of urgency to the Risk Management Strategy Group and addressed though the University's Risk Management Plan and Disaster Recovery Plan.
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}
Security Management Plan, Security Plan, Security Management, INFORMATION SECURITY MANAGEMENT SYSTEM ISMS, PLAN, MANAGEMENT PLAN, Management, Access Management, Risk Management Plan, The Cyber Security Plan Implementation, Cyber Security Plan Implementation Schedule, Security, Project Management Training Program Plan, Project Management Training Program, Project Management Plan, Computer Security Incident Handling Guide