Table of Contents
1. Authority and Review
7
2. Purpose and Objectives
7
3. Standards and Frameworks
8
4. High Level Incident Response Process
8
5. Common Security Incidents and Responses
9
5.1. Common Threat Vectors
9
5.2. Common Cyber Incidents
10
6. Roles and Responsibilities
10
6.1. Points of Contact for Reporting Cyber Incidents
10
6.2. Cyber Incident Response Team (CIRT)
11
6.3. Senior Executive Management Team (SEMT)
12
6.4. Roles and Relationships
13
7. Communications
14
7.1. Internal Communications
14
7.2. External Communications
14
8. Supporting Procedures and Playbooks
15
8.1. Supporting Standard Operating Procedures (SOPs)
15
8.2. Supporting Playbooks
15
9. Sector, Jurisdictional and National Incident Response Arrangements
16
9.1. Sector Arrangements
16
9.2. Jurisdictional Arrangements
16
9.3. National Arrangements
16
10. Incident Notification and Reporting
16
10.1. Legal and Regulatory Requirements
17
10.2. Insurance
17
INCIDENT RESPONSE PROCESS
17
11. Detection, Investigation, Analysis and Activation
17
5