Sainik
Sainik
Sainik
no
Inform functional
Supervisor
unit supervisor
actions.
yes
Is it a
Functional unit
recognized Report
incident to Ongoing
Supervisor yes
security
Security Unit incident
actions.
incident?
no
Verify configuration.
Record current status
of environment.
no
unit monitoring.
hours
Inform
security unit
Incident has been
of un-
no
characterized
characterized
incident
no
yes
Submit incident
documented mitigation yes
procedures to End of incident
report to ISO
steps?
resolve.
ISO
Advise on actions
requested?
to take in the event
a security incident
is established
yes
End of incident
procedure
Mitigate further
Co-ordinate other
Protect and collect all
Communicate to
damage or loss to
resources, SMEs,
available information for
management and
data or the
vendors and
forensic analysis
PIOs
infrastructure
appropriate authorities.
Follow published
Functional unit(s)
structured
for impacted area(s)
methodology Analyze all available
will publish
guidelines and best information
workarounds, fixes
practices
and
recommendations
Implement
Publish new or modify
recomendations.
existing guidelines, best
no
Hold a post incident
practices,
meeting
Restore normal
configurations. and
operations
checklists.
yes
Report out
as
necessary to
Publish Security
CIO and CISO approve management
teams, Incident Report Form. End of incident
recommendations and PIOs and
appropriate Disband incident team.
restoration of service?
authorities