Objective: Reporting information security incidents, assists in maintaining an accurate threat environment picture for government systems using IODEF standard. The requirement to lodge an information security incident report still applies when an agency has outsourced some or all of its information technology functions and services. The CISO is required to keep the CSO and/or Agency Head informed of information security incidents within their agency. The ITSM actively manages information security incidents and must ensure the CISO has sufficient awareness of and information on any information security incidents within an agency. Reporting on low‐level incidents can be adequately managed through periodic (at least monthly) reports. Serious incidents will require more immediate attention. Significant information security incidents must be reported to BCC. The BCC uses these reports as the basis for identifying and responding to information security events across government, for developing new policy, procedures, techniques and training measures to prevent the recurrence of similar information security incidents across government. Reporting of information security incidents to the BCC through the appropriate channels ensures that appropriate and timely assistance can be provided to the agency. In addition, it allows the BCC to maintain an accurate threat environment picture for government systems. In the case of outsourcing of information technology services and functions, the agency is still responsible for the reporting of all information security incidents. As such, the agency must ensure that the service provider informs them of all information security incidents to allow them to formally report these to the BCC. 10.3. Managing Information Security Incidents Objective: Mandatory Control 1: Mandatory Control 2: To identify and implement processes for incident analysis and selection of appropriate remedies which will assist in preventing future information security incidents Agencies must detail information security incident responsibilities and procedures for each system in the relevant SecPlan, SOPs and IRP Agencies must follow IODEF Standard and should include the following information in their register: the date the information security incident was discovered the date the information security incident occurred 44

Select target paragraph3