10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

8.1.3.2 Execute Tests<br />

Completion <strong>of</strong> tests requires appropriate notification throughout the<br />

organization to ensure the test achieves its desired results:<br />

• Provide notice to test participants so that they can plan<br />

workload to ensure availability for the test.<br />

• Provide notice to business and IT operations staff in the event<br />

that the plan inadvertently impacts normal operations.<br />

8.1.3.3 Review Test Results and Take Corrective Action<br />

Once the test has been completed, the results should be reviewed to<br />

see if the IR plan accurately reflects the needs <strong>of</strong> the organization or if<br />

an adjustment is required.<br />

8.1.4. Operate the Plan<br />

No applicable Non-Mandatory Procedures.<br />

8.2. Maintain Records<br />

Agencies should capture documentation appropriate to all incident response<br />

processes:<br />

• Document and retain copies <strong>of</strong> incident response roles, responsibilities,<br />

assigned individuals and appropriate contact information.<br />

• Document and retain copies <strong>of</strong> incident response training materials.<br />

• Document and retain copies <strong>of</strong> the incident response plan, including<br />

preparatory materials.<br />

• Document and retain copies <strong>of</strong> completed incident response tests.<br />

32

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!