10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

work well in such high-stress environments should be<br />

considered.<br />

• IR responsibilities can require the taking <strong>of</strong> quick, decisive<br />

actions based on minimal information and so only those staff<br />

that can communicate efficiently to share maximum<br />

information should be considered.<br />

8.1.1.3 Identify IR Responsibilities <strong>of</strong> those Roles<br />

Once individual employees have been associated with particular<br />

roles, it is important to define and assign specific responsibilities so<br />

that in the event <strong>of</strong> an incident all members <strong>of</strong> the team know who<br />

will be handling what.<br />

8.1.1.4 Build and Deliver an IR Training Program<br />

To ensure that all members <strong>of</strong> the IR team are able to execute their<br />

responsibilities in the most efficient manner possible a training<br />

program must be devised and delivered:<br />

• Determine needs and design a program accordingly.<br />

• Create the materials to support the delivery <strong>of</strong> the training<br />

program.<br />

• Provide instructive training in IR operations as per the<br />

program.<br />

• Provide training support materials in IR operations as per the<br />

program.<br />

8.1.2. Build an Incident Response Capability<br />

Incident response planning requires the identification <strong>of</strong> assets to be protected<br />

by the plan, determination <strong>of</strong> the strategies applicable to the execution <strong>of</strong> the<br />

plan and the documentation <strong>of</strong> the plan itself:<br />

8.1.2.1 Create an Incident Response (IR) Plan<br />

Develop a formal plan that outlines organizational intent in regards to<br />

incidents and the manner in which they will be handled:<br />

• Determine the overall purpose and scope <strong>of</strong> the IR capability.<br />

• Establish the goals <strong>of</strong> the IR capability and the strategies that<br />

will be used to achieve those goals.<br />

• Define appropriate internal and external communications<br />

requirements and mechanisms.<br />

• Define the metrics by which the IR capability will be measured<br />

to determine effectiveness and indicate opportunities for<br />

enhancement.<br />

30

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!