Objective:
Reporting information security incidents, assists in maintaining
an accurate threat environment picture for government systems
using IODEF standard.
The requirement to lodge an information security incident report still applies when an agency has
outsourced some or all of its information technology functions and services.
The CISO is required to keep the CSO and/or Agency Head informed of information security
incidents within their agency. The ITSM actively manages information security incidents and must
ensure the CISO has sufficient awareness of and information on any information security incidents
within an agency.
Reporting on low‐level incidents can be adequately managed through periodic (at least monthly)
reports. Serious incidents will require more immediate attention.
Significant information security incidents must be reported to BCC. The BCC uses these reports as
the basis for identifying and responding to information security events across government, for
developing new policy, procedures, techniques and training measures to prevent the recurrence of
similar information security incidents across government.
Reporting of information security incidents to the BCC through the appropriate channels ensures
that appropriate and timely assistance can be provided to the agency. In addition, it allows the BCC
to maintain an accurate threat environment picture for government systems.
In the case of outsourcing of information technology services and functions, the agency is still
responsible for the reporting of all information security incidents. As such, the agency must ensure
that the service provider informs them of all information security incidents to allow them to
formally report these to the BCC.
10.3.
Managing Information Security Incidents
Objective:
Mandatory Control 1:
Mandatory Control 2:
To identify and implement processes for incident analysis and
selection of appropriate remedies which will assist in preventing
future information security incidents
Agencies must detail information security incident responsibilities
and procedures for each system in the relevant SecPlan, SOPs and
IRP
Agencies must follow IODEF Standard and should include the
following information in their register:
the date the information security incident was discovered
the date the information security incident occurred
44