jagomart
digital resources
picture1_Slideshare Management 75165 | Incident Response Rp Final


 235x       Filetype PPTX       File size 1.73 MB       Source: elpaso.ttuhsc.edu


File: Slideshare Management 75165 | Incident Response Rp Final
purpose review and discuss the it policy and procedure for incident handling and response topics 1 incident management policy 2 incident response procedure it security incident management hscep itp 56 ...

icon picture PPTX Filetype Power Point PPTX | Posted on 02 Sep 2022 | 3 years ago
Partial capture of text on file.
  Purpose
  Review and discuss the IT Policy and Procedure for 
  Incident Handling and Response. 
  Topics
  1.Incident Management Policy
  2.Incident Response Procedure 
       IT Security Incident Management
                     • HSCEP ITP: 56.50.10 Incident Response
       What is an 
        incident?
                     • Determine your role and follow the matrix 
        How do I      of predefined responsibilities.
      respond to it?
     What is an incident?
     The Texas Department of Information Resources defines an incident as: 
       an attempted or successful unauthorized access, use, disclosure, 
       exposure, modification, destruction, release, theft, or loss of 
       sensitive, protected, or confidential information or interference with 
       systems operations in an information system. 
                         -Department of Information Resources, Incident 
                         Response Team Redbook, July 2014
                       What do I do and what is the 
                       process?
                                                                            • Reports abnormal event to IT Help Desk at 915-215-4111, option 1 or 
                                                                               ELP.HelpDesk@ttuhsc.edu.
                                                     System User
                                                     System User
                                                                            • Receives report from system user and notifies Information Security 
                                                                               Office.
                                               IT Helpdesk Personnel
                                               IT Helpdesk Personnel
                                                                             •
                                                                               Validates abnormal event as an incident or not
                                                                             •
                                                                               If event is determined to be an incident, reports to the Information 
                                                   Critical Incident         Security Officer.
                                                   Critical Incident 
                                               Response Team (CIRT)
                                               Response Team (CIRT)
                                                  (First Responder)
                                                  (First Responder)
                                      • Determines level of incident as either small, medium, or large.
                                      • Assigns CIRT lead if incident is classified as medium or higher.
                                      • Activates incident response plan.
                       Information    • Notifies the Chief Information Officer/Information Resources Manager when 
                       Information 
                     Security Officer  incident is classified medium or higher.
                     Security Officer
                                      • Implements remaining phases to handle incident as defined in the incident 
                                       response plan.
                                      • Tracks and documents the incident per the incident response plan.
                       CIRT Team      • Reports incident resolution to the Information Security Officer.
                       CIRT Team
                                       •Validates abnormal event as an incident.
                                       •Reports incident resolution to the Chief Information Officer/Information 
                                       Resources Manager, other executive-level management, and the Department 
                       Information     of Information Resources.
                       Information 
                     Security Officer
                     Security Officer
The words contained in this file might help you see if this file matches what you are looking for:

...Purpose review and discuss the it policy procedure for incident handling response topics management security hscep itp what is an determine your role follow matrix how do i of predefined responsibilities respond to texas department information resources defines as attempted or successful unauthorized access use disclosure exposure modification destruction release theft loss sensitive protected confidential interference with systems operations in system team redbook july process reports abnormal event help desk at option elp helpdesk ttuhsc edu user receives report from notifies office personnel validates not if determined be critical officer cirt first responder determines level either small medium large assigns lead classified higher activates plan chief manager when implements remaining phases handle defined tracks documents per resolution other executive...

no reviews yet
Please Login to review.