Security Incident Hand-off
"Organization QWERTY Data loss for 10,000 record and its share value may drop " Rumor inside.
I personally prefer to do "Security Hand-Off process" while identifying the security incident based on the nature and directly impact the reputation or share values should be handled by experts from cyber security incident management ( like IBM CERT and ERS) and organization's CISO to lead the situation. Its mandate to have participation from customer side to validate the impact and its take necessary actions.
Of course, among IT and Incident management peoples should have proper education on Cyber security and how to handle such substations and avoid rumor's. Which help organization to contain the situation to controlled manner to take right action.
Then general incident team make such issues as noise and spread unhealthy news across and lead to dis agreed messages to outsides. and even some best practices in general Incident management practice need to be customized for Security incident management and controlled manner.
Severity one ticket for Data Loss for your Organization ! Or for service outage due to Denial of Service ! And doing SMS notification to entire Organization as part of general priority Incident management process !!!
Yes, even controlled manner still IT and employees have limited visibility which cause unhealthy environment for organization hence regular genuine update to employees and IT is preferred.
** Above is my personal views and viewpoints only
Comments
Post a Comment