Incident Response Policy
Purpose
This document describes the responsibilities of all the members of the SAKEC for responding
and reporting information security incidents.
Applicability
This policy will apply to everyone who uses it to store, transmit, process and access the SAKEC
data. That person can be SAKEC employees, students, temporary workers, contractors, and
everyone who is authorized to access the SAKECs information or assets.
Definitions
● Event: The security event is described as the occurrence or change of a particular set of
circumstances. Events can have a positive or negative cause. When something happens
it’s an event.
● Incident: An incident can be anything such as unauthorized access, destruction of
information, data breach, computer system breach, etc.
● Information security: Preservation of confidentiality, integrity, and availability of
information.
● information security incident: single or a series of unwanted or unexpected information
security events that have a significant probability of compromising business operations
and threatening information security.
● Incident response: It is a set of information security policies and procedures that you can
use to limit or eliminate security breaches.
Policy Statement:
2. All the members of the SAKEC must responsibly report any suspected or confirmed data
breaches or any kind of security incident that involves SAKEC data, the incident must be
reported in brief to the responsible team.
3. All the members must cooperate with the team which is responsible to handle the incident, no
individual must interfere, obstruct, or prevent the smooth flow of incident investigations.
4. During the incident investigation the responsible team is authorized to retrieve any
communications or any other relevant records which are related to the incident without any
further notice or approval.
5. All the members of the SAKEC should participate in training, awareness, and exercise that is
related to incident response to strengthen the SAKEC's ability to handle the data.
6. SAKEC must make sure that any such training programs organized are well-promoted to all
the members of the SAKEC.
7. Failure to adhere to policies may be met with SAKEC sanctions, and will also result in
disciplinary actions.