« Back to DataSecurityPolicies.com

Incident Response Policy from Yale

Here’s the incident response policy used at Yale.

Parts of the policy include:

  • Identification of Incidents
  • Establishment of an IT Security Incident Response Team
  • Risk Assessment Classification Matrix
  • Documentation and Communication of Incidents
  • Subordinate Procedures
  • Role of Yale Personnel, Training
  • Incident Prevention

This is an exerpt from the Risk Assessment section:

The ISO will establish an internal risk assessment classification matrix to focus the response to each Incident, and to establish the appropriate team participants to respond. This classification matrix will correspond to an “escalation” of contacts across the University, and will indicate which authorities at Yale to involve and which procedure would be applicable for each class of incident.

An archived copy of the policy is here.

Leave a Reply