Incident Response Policy
John Cristiansen is an information security compliance and risk management lawyer in Seattle, WA. He has an excellent example of a generic Security Incident Reponse Policy on his blog here. The policy is focused on complying on HIPAA requirements but it can be customized to meet the needs of any organization.
Here’s an exerpt:
1. Objectives of this Policy
The objectives of this Policy are to help assure:
- The confidentiality, integrity and availability of Protected Information held by ORGANIZATION, including but not limited to protected health information as defined by Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (”HIPAA”); and
- The operational integrity of ORGANIZATION’s Information Systems.
2. Scope of Policy
This Policy is intended to help accomplish its objectives by providing guidance to ORGANIZATION Workforce and Contractors, so that they will be able to:
- Recognize events or circumstances which may indicate that a Security Incident is occurring or has occurred;
- Know who is responsible for and authorized to respond to possible Security Incidents; and
- Know the procedures which should be followed in responding to possible Security Incidents.