View on GitHub

Reprotec UK Ltd Policies Home Page

Home page for ISO and employee policies

Security Incident Reporting

Introduction

Opus Works has established a formal policy and supporting procedures in the event of a Security Incident.

Procedure

All Opus Works employees should be aware of common security threats and computer incidents that may potentially compromise the organisation’s computing infrastructure, cause harm to other related systems or pose a significant financial, operational or business threat to the organisation as a whole.

It is the responsibility of all staff to report security risks and incidents to the ISMS Committee.

The ISMS Committe will choose whether to form a Security Incident Response team in response to the report, formed from employees and other external groups if required (e.g. external security specialists).

Security Incident Response Team

Detection

Detection may occur in several ways:

Response

The ISMS Manager will evaluate reports of incidents and decide whether to notify the ISMS Committee.

If notified, a suitable member of the ISMS Committee formally assumes control and is tasked with identifying the threat and its severity to the organisation’s information systems and reporting back to the ISMS Committee.

The selected ISMS member is to make a determination if the resources at risk (hardware, software, etc.) require physical or logical removal. Resources which pose a significant threat to the continuity of the business are to be immediately removed or isolated, either physically or logically.

A response plan should be proposed to deal with potential risk identified. This may need to be authorised by the ISMS Committee before implementation. This plan should include:

The Security Incident Log can be found here - Needs a link

It is the responsibility of the ISMS Committee to ensure that an investigation can follow the incident. For example by:

Recovery

Recovery procedures may include, but are not limited to the following:

The recovery procedures will be commensurate with the incident that has occurred. This will be conducted on a case-by-case basis with all aspects of the recovery process fully documented.

Post-Incident Review

A formal and documented Incident Response Report (IRR) is to be compiled and given to the ISMS Committee within an acceptable time frame following the incident. The IRR must contain the following elements:

back