Topic ITSM Procedures to be included in the SOPs System administrators recovery including audit logs Securing backup tapes Recovering from system failures N/A Acceptable uses of the system(s) N/A How to secure systems at the end of the day N/A Procedures for handling and using media Acceptable Use N/A End of Day N/A Media Control N/A Passwords N/A N/A Temporary absence N/A N/A 8.6. System users Choosing and protecting password(s) How to secure systems when temporarily absent Incident Response Plans (IRP) Objective: Mandatory Control 1: Incident Response Plans (IRP) outline actions to take in response to an information security incident Agencies must include, as a minimum, the following content within their IRP: broad guidelines on what constitutes an information security incident the minimum level of information security incident response and investigation training for system users and system administrators the authority responsible for initiating investigations of an information security incident the steps necessary to ensure the integrity of evidence supporting an information security incident the steps necessary to ensure that critical systems remain operational when and how to formally report information security 35

Select target paragraph3