10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

8.1.2.e IR Plan Update Scheduling and Frequency<br />

• IR plans should be reviewed and updated on an at least annual<br />

basis or at such time as IR testing or IR operations indicate a<br />

deficiency in the IR plan.<br />

8.1.3. Test the Plan<br />

To ensure the applicability <strong>of</strong> the plan and to verify that the plan can be acted<br />

upon as created, periodic testing should be performed:<br />

8.1.3.a IR Testing Methodologies<br />

• The following capabilities should be included in the IR testing<br />

program:<br />

o Recognition <strong>of</strong> externally and internally sourced<br />

incidents.<br />

o Analysis to gather incident identification information.<br />

o Application <strong>of</strong> containment and eradication tasks<br />

appropriate to the type <strong>of</strong> incident.<br />

o Restoration <strong>of</strong> normal operations.<br />

o Co-ordination and communications.<br />

• IR testing can be conducted in one <strong>of</strong> two ways:<br />

o Classroom or tabletop exercises walkthrough IR<br />

operations without any IR operations occurring.<br />

o Functional or simulation exercises recreate actual<br />

incidents and require the execution <strong>of</strong> IR operations.<br />

8.1.3.b IR Testing Scheduling and Frequency<br />

• Classroom or tabletop exercises should be performed on at<br />

least an annual basis.<br />

• Functional or simulation exercises should be performed on at<br />

least a tri-annual basis.<br />

8.2. Operate the Plan<br />

No applicable Non-Mandatory Baselines.<br />

8.3. Maintain Records<br />

Agencies should capture documentation appropriate to all incident response<br />

processes:<br />

• Document and retain copies <strong>of</strong> incident response roles, responsibilities,<br />

assigned individuals and appropriate contact information.<br />

• Document and retain copies <strong>of</strong> incident response training materials.<br />

• Document and retain copies <strong>of</strong> the incident response plan, including<br />

preparatory materials.<br />

• Document and retain copies <strong>of</strong> completed incident response tests.<br />

27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!