Objective:
Mandatory Control 3:
Mandatory Control 4:
Mandatory Control 5:
Mandatory Control 6:
Recommended Control 1:
Recommended Control 2:
To identify and implement processes for incident analysis and
selection of appropriate remedies which will assist in preventing
future information security incidents
a description of the information security incident, including
the personnel, systems and locations involved
the action taken
to whom the information security incident was reported
the file reference
Agencies must implement procedures and processes to detect data
spills. Agency SOPs must include procedure for:
all personnel with access to systems
notification to the ITSM of any data spillage
notification to the ITSM of access to any data which they
are not authorised to access
Agencies must document procedures for dealing with data spills in
their IRP
Agencies must treat any data spill as an information security
incident and follow the IRP to deal with it
When a data spill occurs agencies must report the details of the
data spill to the information owner
Agencies should ensure that all information security incidents are
recorded in a register
Agencies should follow the steps described below when malicious
code is detected:
isolate the infected system
decide whether to request assistance from BCC
if such assistance is requested and agreed to, delay any
further action until advised BCC
scan all previously connected systems and any media used
within a set period leading up to the information security
incident, for malicious code
isolate all infected systems and media to prevent
reinfection
change all passwords and key material stored or potentially
accessed from compromised systems, including any
websites with password controlled access
advise system users of any relevant aspects of the
compromise, including a recommendation to change all
passwords on compromised systems
use up‐to‐date antivirus software to remove the infection
from the systems or media
monitor network traffic for malicious activity
45