Skip to main content

Information Security Incident Response Plan

Effective Date: January 21, 2019

Introduction

This Incident Response Plan (IRP) describes the overall plan for responding to information security incidents at the University. It defines roles and responsibilities, what reporting requirements are and what characterizes an incident. This plan defines how to report, react to, mitigate, communicate and close an information security incident.

Definitions

Event

An event is any exception to the normal operation of an information system. Events may be reported in a variety of ways including direct reports from University constituents, reports from external sources and reports from automated management and detection systems. Not all events become incidents.

Vulnerability

A vulnerability is any condition in an information system, process, procedure or control that could be exploited by a threat source to cause an information security event or incident.

Incident

An incident is an event or condition that when assessed by Office of Information Technology staff, violates Operations Manual section 9, “Information Technology Policies,” or threatens the confidentiality, integrity or availability of a University information system or University data.

Incidents will be prioritized according to the depth and breadth of potential for University-classified data exposure and the impact to the University mission of the information system affected.

Impact
High Medium Low
Data Exposure High Critical High Medium
Medium High Medium Medium
Low Medium Medium Low

Detected or reported vulnerabilities and events may not be classified as incidents if the actual risk of data exposure or impact on information system operation is low or non-existent.

Roles and Responsibilities

Incident Response Coordinator

The IRC is the OIT employee who is responsible for assembling all the data pertinent to an incident, establishing communication with appropriate parties and reporting on incident status during and at the conclusion of the incident response process. Most often, this role will be filled by the Director of Network Services and Information Security with a backup of the Vice President for Information Technology..

Incident Response Handler

The IRH(s) are University staff or outside contractors who gather and preserve evidence, analyze evidence and/or make efforts to restore University information systems and data back to their pre-incident state of service. Most often, this role will be filled by an Information Security Analyst with a backup of the Director of Network Services and Information Security.

Insider Threats

Insiders are any current or former University constituents who may have currently or in the past non-public knowledge of the University’s information systems or data. This role is identified here because Insider Threats require special organizational and technical amendments to normal IRP procedures.

Law Enforcement

Any Federal or State law enforcement agency or other United States Government agency that presents warrants or subpoenas for the disclosure of information. Interactions with these groups must always follow the IT Request from Law Enforcement flowchart.

Users

Users are members of the University community or anyone accessing an information system or data for which the University is responsible.

Methodology

This plan outlines the most general tasks and requirements for Incident Response and may be supplemented by internal specific procedures or guidelines. These procedures and guidelines will be subject to amendment as technology and recommended practices change over time.

Evidence Preservation

The goal of Incident Response is to reduce and contain the scope of an incident and return access (data or information systems) to normal service as quickly as possible. This rapid response is balanced by the potential requirement to collect and preserve evidence and abide by legal and administrative requirements for documenting chain of custody. In the absence of explicit instruction by the Incident Response Coordinator to the contrary, the Incident Response Handler will presume all efforts to preserve evidence and chain of custody should be undertaken.

Incident Response Process Phases

As defined in NIST Special Publication 800-61 Rev 2 (Computer Security Incident Handling Guide), the incident response process consists of six phases: Preparation, Detection, Containment, Investigation, Remediation, and Recovery.

Preparation

Preparation includes activities that prepare the University to respond to an incident. These include establishing policy and procedures, gathering tools, receiving training and establishing communication plans. Adjustments to preparation may occur as part of the response to an incident based on lessons learned in the Recovery Phase.

Detection

Detection is the discovery of an event that may be an incident. This detection may be via automated or other tools, may be a direct source of information either internal or external to the University. During the detection phase, an incident is declared if appropriate and its classification is established.

Containment

During containment, the affected information system is identified and isolated or otherwise mitigated to prevent further risk to the confidentiality, integrity or availability of the data. Communication to appropriate parties will occur during this phase, as well as evidence collection and escalation to other entities such as legal counsel or law enforcement.

Investigatio

During the investigation, priority, scope and root cause(s) are determined and documented.

Remediation

In remediation, affected information systems and/or policies and procedures are repaired and or revised to prevent future incidents based on the root cause(s) determined during the Investigation. A determination will be made as to whether or not there are regulatory requirements for reporting the incident to outside parties and if needing the reporting will be completed.

Recovery

Recovery is the analysis of the incident for its policy and procedural implications and the incorporation of “lessons learned” into future response and training efforts.

Guidelines for the Incident Response Process

Every incident can bring about questions and problems that have not previously been encountered. Below are a few of the most common issues that arise. The Director of Network Services and Information Security and the Vice President for Information Technology should be consulted for questions and incident types not covered by these guidelines.

Insider Threat

In the case that an individual who may typically be an Incident Response Handler is a person of interest in an incident, the Incident Response Coordinator will assign another appropriate staff member to perform the incident response, or will assume the role of Incident Response Handler and delegate the Incident Response Coordinator role to the Vice President for Information Technology.

In the case where the Incident Response Coordinator is a person of interest in an incident, the Vice President for Information Technology will act in their stead.

In the case where the Vice President for Information Technology is a person of interest in an incident, the Incident Response Coordinator will work directly with the Vice President for Information Technology’s direct supervisor.

In the case where the President is a person of interest in an incident, the Vice President for Information Technology will work directly with the Chair of the Board of Trustees or a designee thereof.

Interactions with Law Enforcement

All communications with external law enforcement must adhere to the process established by the Information Technology Requests From Law Enforcement document.

Communications Plan

All public communications to parties outside of the University will be guided by the University Crisis Communication Plan with the involvement, if necessary, of University Counsel. At no time will any University employee be permitted to provide communications about an incident outside the University without the approval of the Vice President for External Relations and/or University Counsel. This includes communications to law enforcement, mass media or social media outlets.

Internal communications regarding an incident are to be provided only to affected or otherwise interested parties and contain the minimum amount of information necessary to achieve the objective. Establishing this minimum amount of information is accomplished via consultation with the Vice President for Information Technology, University Counsel and/or other members of the University senior leadership.

Privacy

All actions undertaken during an Incident Response will comply with the University Data Privacy policy, OM 9.1.5.

Documentation, Tracking, and Reporting

All activities associated with Incident Response will be documented and artifacts retained based on methods consistent with legal, chain of custody and confidentiality requirements. A mandatory level of documentation and tracking will include the metadata of the event, decision points for the establishment of an incident and metadata about the progression through the Incident Response life cycle. Additional documentation may be required by the Incident Response Coordinator based on the circumstances of the specific incident.

Escalation

At any time during Incident Response, the Incident Response Coordinator, Director of Network Services and Information Security, and the Vice President for Information Technology may be called upon to escalate any issue pertaining to the incident. The Director of Network Services and Information Security and the Vice President for Information Technology in consultation with University Counsel will determine if or when an incident or aspect of an incident response should be escalated to external authorities.

Additional Information

Additional information about the Incident Response Plan can be obtained by contacting the Office of Information Technology via helpdesk@clarkson.edu or (315)268-4357

Revision History

1.1 - October 2023 - Joshua A. Fiske, Vice President for Information Technology
1.0 - January 2019 - Brian T. Huntley, Director of Network Services and Information Security