| Author: | Richard Gadsden |
|---|---|
| Contact: | gadsden@musc.edu |
| Version: | 0.2 |
| Date: | 23 May 2005 |
| Status: | DRAFT |
The purpose of these standards is to document the minimum requirements for responding to information security incidents that affect or involve any MUSC information asset, and/or any device that is connected to MUSC's network.
The CSIRT is responsible for:
All security incidents that affect or involve any MUSC information assets must be reported to the CSIRT.
If an MUSC system, or any system connected to MUSC's network, is involved in or affected by a security incident, then the System Owner and/or the System Administrator is expected to coordinate all incident response activities with the MUSC CSIRT.
All workforce members are required to follow the Computer Security Incident Reporting Procedures to report any known or suspected security breach or compromise that involves or affects any MUSC system. Workforce members must also report, through appropriate channel(s), any serious vulnerability that is observed to affect an MUSC system.
All security incidents that affect or involve any MUSC information assets must be reported to the MUSC CSIRT, following the procedures defined in the Computer Security Incident Reporting Procedures.