Name: BENJAMIN A.
PARIÑAS Date: 10/21/25
Instructor: MR. JOHN MICHAEL CUTAMORA
Course and Section: IT107 (INFORMATION ASSURANCE AND SECURITY 1) - IO1
Part I – Scenario-Based Questions
Scenario: The ICT Center of Caraga State University experienced a sudden server outage caused
by a power fluctuation. No data was lost, but several systems went offline for hours. The ICT Head
now wants to prepare a Contingency and Incident Response Plan to prevent future disruptions.
Guide Questions:
1. What are the main goals of an incident response plan?
➢ The main goal of an Incident Response Plan is to ensure that when an incident happens, the
organization can react quickly, minimize the damage, and return to normal operations as
soon as possible. As Whitman and Mattord describe, an effective incident response plan
focuses on detecting, containing, and recovering from incidents while preserving evidence
for future analysis.
In simpler terms, it serves as a blueprint for action during unexpected situations. It helps the
ICT team stay organized when facing server outages, cyberattacks, or hardware failures. For
Caraga State University, this means ensuring that even if systems go offline, the university
can continue its essential tasks like enrollment, research access, and communication.
Personally, I believe the IRP’s greatest value lies not only in restoring systems but also in
maintaining confidence both among the ICT staff and the users who depend on their
services. It’s about being prepared to act calmly instead of reacting with panic.
2. What steps should the ICT Center take immediately after detecting the incident?
➢ When an incident such as a power-related server outage occurs, the ICT Center must follow
structured steps to ensure the situation doesn’t worsen. The first step is verification, which
means confirming that the incident is real and understanding its extent. This avoids wasting
time on false alarms. Next is containment, where the team isolates affected servers or
systems to prevent further damage. For instance, ICT staff could switch to backup power
sources or shut down unstable equipment to protect it.
After that, they should notify the key personnel, including the ICT Head, system
administrators, and possibly the university’s management, to ensure that everyone is aware
of the problem. Once the issue is contained, the next step is investigation and
documentation, which involves recording what happened, when it happened, and what was
affected. This information is crucial for diagnosing the root cause and preventing recurrence.
Finally, they should eradicate the problem, recover systems, and conduct a post-incident
review to evaluate what worked and what didn’t.
From my point of view, having these steps written down and practiced is essential. In
stressful moments, people can forget even simple actions. A documented process ensures
that the team can act systematically, saving both time and resources. It also strengthens
accountability, since everyone knows their exact role when an incident occurs.
3. What information should be included in a contingency plan?
➢ A contingency plan serves as a safety net, a detailed guide on how to keep the organization
running when something goes wrong. According to Module 5: Fundamentals of Contingency
Planning (Whitman & Mattord, 2022), it should include clear sections on the plan’s purpose
and scope, the roles and responsibilities of key staff, contact information, and procedures
for backup and recovery. It should also outline alternative sites or systems, a
communication plan for notifying users and stakeholders, and a testing and training
schedule to ensure everyone knows what to do.
For the ICT Center of Caraga State University, this would mean listing not only technical
instructions but also practical arrangements like who will contact the electric company,
who will initiate backup servers, and who will send updates to affected departments.
Personally, I think the strength of a contingency plan lies in its clarity. During emergencies,
people need straightforward guidance, not complicated instructions. The more specific and
easy to follow the plan is, the faster the team can restore stability. It’s like having a map
when lost you may still face challenges, but at least you know the direction forward.
4. Why is testing the plan important before an actual incident occurs?
➢ Testing is one of the most critical, yet often neglected, parts of contingency and incident
response planning. According to Whitman and Mattord, testing ensures that plans work in
practice and not just on paper. Without testing, even the best-written plans can fail when
stress, time pressure, and real technical issues come into play.
By conducting regular tests or simulations, the ICT Center can identify weaknesses like for
instance, outdated contact information, non-functional backup servers, or unclear
instructions. Testing also helps build confidence and teamwork, as staff members learn
their roles and become comfortable handling emergencies. Moreover, it ensures that all
resources from hardware to documentation are working as intended.
In my view, testing is like a “rehearsal” before a live performance. You don’t want to figure
out your lines when the show has already started. Through testing, the team learns how to
respond naturally and efficiently. It’s not about predicting every possible event but about
building the readiness and coordination needed to adapt quickly.