0% found this document useful (0 votes)
32 views24 pages

Data Loss Incident Response Playbook

Uploaded by

0201ip201020
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
32 views24 pages

Data Loss Incident Response Playbook

Uploaded by

0201ip201020
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Data Loss Control Playbook

Data Loss Playbook OFFICIAL 1


Contents
1. Introduction ................................................................................................................................................................................................... 3
1.1. Overview................................................................................................................................................................................................ 3
1.2. Purpose ................................................................................................................................................................................................. 3
1.3. Data Breach Definition ............................................................................................................................ Error! Bookmark not defined.
1.4. Scope .................................................................................................................................................................................................... 3
1.5. Review Cycle ......................................................................................................................................................................................... 4
2. Preparation Phase ........................................................................................................................................................................................ 5
3. Detect ........................................................................................................................................................................................................... 7
4. Analyse ....................................................................................................................................................................................................... 13
5. Remediation – Contain, Eradicate and Recover .......................................................................................................................................... 17
6. Post Incident ............................................................................................................................................................................................... 22
7. Annex A: Flow Diagram .............................................................................................................................................................................. 24

Data Loss Playbook OFFICIAL 2


1. Introduction
1.1. Overview
In the event of a cyber-incident, it is important that the organisation is able to respond, mobilise and execute an appropriate level of response to
limit the impact on the brand, value, service delivery and the public, client and customer confidence. Although all cyber incidents are different in
their nature and technologies used, it is possible to group common cyber incidents types and methodologies together. This is in order to provide
an appropriate and timely response depending on the cyber incidents type. Incident specific playbooks provide incident managers and
stakeholders with a consistent approach to follow when remediating a cyber-incidents.
References are made to both a Core IT CIRT and a CIRT within this document. This is in recognition of the fact that organisations are different
and will be their own response to cyber incidents. Some may initially manage an incident with a small response team within IT services but where
there is a confirmed compromise this may be escalated to an extended level CIRT comprised of members of the organisation outside IT services
who will deal with agreed categories of compromise. The Playbook as with the Cyber Incident Response Plan (CIRP) will require to be adjusted
to reflect the organisational make up.
Playbooks describe the activities of those directly involved in managing specific cyber incidents. However, it is important to acknowledge the
speed at which cyber incidents can escalate and become a significant business disruptor requiring both business continuity and consequence
management considerations. Early consideration should be given to engaging Business Continuity, Resilience and Policy Area Leads in order
that the wider issues can be effectively managed. Business Continuity and Resilience leads within the organisation must therefore be familiar
with the Cyber Incident Response Plan (CIRP) and Playbooks and how they link to wider Incident response arrangements.

1.2. Purpose
The purpose of the Cyber Incident Response: Data Loss Playbook is to define activities that should be considered when detecting, analysing and
remediating a Data Loss incident. The playbook also identifies the key stakeholders that may be required to undertake these specific activities.

Scope
This document has been designed for the sole use of the first responders such as the Service Desk team when responding to a cyber-incidents.
It is not standalone and must be used alongside your CIRP.
There are similar play books available as part of this project including but not limited to: Phishing, Malware and Ransomware. The appropriate
playbook should be used for the appropriate incident type.

Data Loss Playbook OFFICIAL 3


1.3. Review Cycle
This document is to be reviewed for continued relevancy by the Cyber Incident Response Team (CIRT) lead at least once every 12 months;
following any major cyber incidents, a change of vendor, or the acquisition of new security services.

Data Loss Playbook OFFICIAL 4


2. Preparation Phase
Preparation Phase
The preparation phase has the following objectives:
Phase • Prepare to respond to cyber incidents in a timely and effective manner;
objectives • Inform employees of their role in remediating a Data Loss incident including reporting mechanisms.

Activity Description Stakeholders

Activities may include, but are not limited to:

• Head of Information Governance


• Head of IT
• Information Security Manager
• Team Leader
Review and rehearse cyber incidents response procedures • Service Delivery Manager
including technical and business roles and responsibilities, • Service Desk Analysts/Technicians
escalation to major incident management where necessary. • Legal Team
Prepare to • Communications Team
respond • Resilience Lead
• Business Continuity Lead

Review recent cyber incidents and the outputs. • Information Security Manager

Review threat intelligence for threats to the organisation, brands


and the sector, as well as common patterns and newly developing • Information Security Manager
risks and vulnerabilities.

Data Loss Playbook OFFICIAL 5


Ensure appropriate access to any necessary documentation and
information, including out-of-hours access, for the following:
• CIRP; • Information Security Manager
• <<Network Architecture Diagrams>>; ( insert Links)
• <<Data Flow Diagrams>>.( insert Links)

Identify and obtain the services of a 3rd party Cyber Forensic • Information Security Manager
provider.

Define Threat and Risk Indicators and Alerting pattern within the
organisation’s security information and event management (SIEM) • Information Security Manager
solution.

Where linked to extortion demand and ransomware attack pre • Information Security Manager
define general parameters of a Data Leak and Recovery Plan • Senior/ Gold Command Team

Where linked to extortion demand and ransomware attack pre-


define parameters of Threat Actor Engagement Plan to cover
instances and considerations around engagement of any Threat
Actor. Activities may include, but are not limited to:;
• General circumstances in which a Threat Actor would be
engaged
• Who would undertake the engagement ( CIR etc.) • Information Security Manager
• Purpose of engagement - delay, intent to pay, proof of • Senior/ Gold Command Team
data exfiltrated, plead etc.
• How exchanges will be recorded
• Defining Stakeholders to be involved specifically advice
offered by Police Scotland
• Understanding wider potential political ramifications of
engagement

Data Loss Playbook OFFICIAL 6


Activity Description Stakeholders

Activities may include, but are not limited to:

Conduct regular awareness campaigns to highlight • Head of IT


cyber/information security risks faced by employees, including: • Information Security Manager
• Legal and regulatory requirements around data security; • Resilience Lead
• Phishing attacks and malicious emails; • Business Continuity Lead
• Ransomware;
Inform • Reporting a suspected cyber incidents.
employees
• Head of IT
• Information Security Manager
• HR
Ensure regular security training is mandated for those employees • L&D Department
managing personal, confidential or high risk data and systems. • Resilience Lead
• Business Continuity Lead

Conduct exercising against this scenario at Tactical, Operational • Conduct exercising against this scenario at Tactical,
and Strategic levels. Consider use of the NCSC Exercise in a Box Operational and Strategic levels. Consider use of the
Toolkit and or access to NCSC Exercising Assured Service NCSC Exercise in a Box Toolkit and or access to
NCSC Exercising Assured Service

3. Detect
Detection Phase

Phase objectives The detection phase has the following objectives:

Data Loss Playbook OFFICIAL 7


• Detect and report a breach or compromise of the confidentiality, integrity or availability of organisational/personal
data;
• Complete initial investigation of the Data Breach or compromise;
• Report the Data Breach or compromise formally to the correct team as a cyber-incidents.

Activity Description Stakeholders

Activities may include, but are not limited to:

Monitor detection channels, both automatic and manual, customer and staff
channels and social media for indications of a Data Breach or compromise, these
can include but are not limited to:
• Customers, employee or confidential data published online;
• Clients or their customers being contacted by an unauthorised third party with
access to personal or confidential information; • Information Security Manager
• Targeted emails to clients or employees containing personal or confidential • Core IT CIRT
information;
• Data loss prevention logs or alerts;
Detect and report • Lost or stolen devices containing confidential information;
the incident • Lost or stolen paperwork or hardcopies of data;
• Other incidents that suggest data has been extracted outside of the network
perimeter.

Report the cyber incidents via the Service Desk. If a ticket does not exist already,
raise a ticket containing minimum information. • Information Security Manager
To report an incident, follow the process defined in the CIRP (Insert link to CIRP • Core IT CIRT
here).

Classify the cyber incidents, based upon available information related to the Data • Information Security Manager#
Loss and the incident types (see CIRP). • Core IT CIRT

Data Loss Playbook OFFICIAL 8


Report the Cyber incidents in accordance with the organisation’s CIRP.
Consider the Intelligence value to other organisations and share on the CISP
• Information Security Manager#
For public sector organisations only: Consider whether the Incident meets
notification threshold within the Scottish Public Sector Cyber Incident Coordination • Core IT CIRT
Procedure as contained within the CIRP.

• Information Security Manager


Where appropriate consider reporting requirements to Information Commissioner’s
• CIRT
Office (ICO), relevant regulator and or Competent Authority (NISD), National Cyber
• Resilience Lead
Security Centre (NCSC), Police Scotland and Scottish Cyber Coordination Centre
(SC3) • Business Continuity Lead
• Policy Area Lead

Activity Description Stakeholders

Activities may include, but are not limited to:

• Information Security Manager


• Core IT CIRT

The following may also be included


Initial Mobilise the CIRT to begin initial investigation of the cyber incidents (see staff in the incident response team where
investigation of appropriate for the incident:
contact details within CIRP).
the incident • Service Desk Analysts
• Server Desk Technicians
• Server Team
• Mobile Device Team

• Information Security Manager


Identify likelihood of employee involvement and notify HR (e.g. insider threat). • Core IT CIRT

Data Loss Playbook OFFICIAL 9


• HR

Collate initial incident data including as a minimum for the following;


• How was the cyber incidents reported;
• What has caused the cyber incidents (i.e. lost laptop, suspected hacker,
malware. Etc.);
• Location of data, both physical and logical;
• Quantity of data i.e. number of accounts, unique numbers, client names; • Information Security Manager
• Is financial data included? I.e. credit card numbers, pins, expiry dates, etc.? • Core IT CIRT
• Is personal data included? I.e. names, address, postcodes, email address,
etc.?
• What is the format of the data i.e. redacted, encrypted, layout, length, etc.?
• Was there any encryption around the data and if so how was this provided?
• Preliminary business impact assessment; and
• Any current action being undertaken.

Secure artefacts, including copies of the data, via secure download and • Information Security Manager
screenshot. • Core IT CIRT

Review critical systems and assess for any indicators of similar data sets being • Information Security Manager
compromised. • Core IT CIRT

• Information Security Manager


Identify possible sources or owners of the data. • Core IT CIRT

Preliminary review of data involved to determine if personal data has been • Information Security Manager
compromised. • Core IT CIRT

Research Threat Intelligence sources and consider Cyber Security Information • Information Security Manager
Sharing Partnership (CiSP) submission to gain further intelligence and support • Core IT CIRT
mitigation by others.

Data Loss Playbook OFFICIAL 10


Review cyber incidents categorisation to validate the cyber incidents type as a • Information Security Manager
Data Loss incident and assess the incident priority, based upon the initial • Core IT CIRT
investigation. (See CIRP for Incident Severity Matrix)

Activity Description Stakeholders

Activities may include, but are not limited to:

• Information Security Manager


Report the cyber incidents in accordance with the organisation’s CIRP.
• Core IT CIRT
• CIRT

• Head of IT
Immediately report Data Breaches that have occurred to the relevant Data
• Information Security Manager
Protection Officer.
• CIRT
Consider whether reporting suspected or confirmed unauthorised access to any • Head of Information Governance
personal data to the authority is appropriate at this stage. • Data Protection Officer

Incident reporting Where appropriate consider reporting requirements to Information Commissioner’s • Head of IT
Office (ICO), relevant Regulator and or Competent Authority (NISD), National • Information Security Manager
Cyber Security Centre (NCSC), Police Scotland and Scottish Cyber Coordination • CIRT
Centre (SC3) • Head of Information Governance
• Data Protection Officer

Report the Cyber incidents in accordance with the organisation’s CIRP.


For public sector organisations only: Consider whether the Incident meets the
• Information Security Manager
reporting threshold within the Scottish Public Sector Cyber Incident Coordination
• Core IT CIRT
Procedure as contained within the CIRP.
• CIRT
Consider the Intelligence value to other organisations and share on the Cisp

Data Loss Playbook OFFICIAL 11


Activity Description Stakeholders

Activities may include, but are not limited to:


Establish the
requirement for a
full forensic Consider conducting a full forensic investigation, on the advice of legal counsel. • Information Security Manager
investigation All evidence handling should be done in line with the Association of Chief Police • Core IT CIRT
Officers (ACPO) Good Practice Guide for Digital Evidence.

Data Loss Playbook OFFICIAL 12


4. Analyse
Analysis Phase
The analysis phase has the following key objectives:
• Analyse the cyber incidents to uncover the scope of the attack;
Phase objectives • Identify and report potentially compromised data and the impact of such a compromise;
• Establish the requirement for a full forensic investigation;
• Develop a remediation plan based upon the scope and details of the cyber incidents.

Activity Description Stakeholders

Activities may include, but are not limited to:

Confirm any data involved is: • Head of IT


• Legitimate; • Information Security Manager
• Current; • Head of Information
Governance
• Originating from the organisation;
• Core IT CIRT
• Connected to the organisation or its Clients or their Customers.
Analyse the
extent of the Conduct a detailed technical investigation of the cyber incidents which may include,
incident but is not limited to:
• Analyse any suspicious network traffic;
• Review security and access logs, vulnerability scans and any automated tool • Information Security Manager
outputs; • Core IT CIRT
• Analyse any suspicious activity, files or identified malware samples;
• Review AV logs or events, without jeopardising future forensic activities;
• Correlate any recent security events, or indicators of compromise, with
suspicious activity seen on the network;

Data Loss Playbook OFFICIAL 13


• Identify the source of the data compromise;
• Identify the specific data set which was compromised as well as how it was
compromised.

• Information Security Manager


Determine the attack methodology and cyber incidents timeline. • Core IT CIRT

Analyse the data types and quantities to determine if there has been a privacy • Information Security Manager
breach (i.e. involving personal data). • Core IT CIRT

Analyse the data types and quantities to determine if there has been a breach of • Information Security Manager
financial data (e.g. organisational financial reports, customer or employee credit • Core IT CIRT
card details, bank details etc.).

Analyse the data types and quantities to determine if the data is only found in the • Information Security Manager
organisation’s environments, or shared with third party systems. • Core IT CIRT

• Information Security Manager


Review the data type and quantity compromised for any compliance regulations • Core IT CIRT
that have been breached. • CIRT

Activity Description Stakeholders

Activities may include, but are not limited to:

Identify and • Information Security Manager


report potentially Engage data owners and senior stakeholders to understand the business impact • Core IT CIRT
compromised of the compromised data. • CIRT
data
• Information Security Manager
Report the cyber incidents in accordance with the CIRP, as required. • Core IT CIRT

Data Loss Playbook OFFICIAL 14


• CIRT

• Information Security Manager


Establish the likelihood that confidentiality, integrity or availability has been • Core IT CIRT
compromised. • CIRT

• Information Security Manager


Consider whether reporting suspected or confirmed unauthorised access to any • Core IT CIRT
personal data to the authority is appropriate at this stage. • CIRT

• Information Security Manager


Update the senior stakeholders (see CIRP) of any suspected or confirmed Data • Core IT CIRT
Breach including the unauthorised access to any personal data. • CIRT

In line with the GDPR (Article 33) the ICO must be informed within 72 hours of the
organisation becoming aware of an incident resulting in a “risk to the rights and • Information Security Manager
freedoms of those involved”. • CIRT
Determine whether the Data Breach needs to be reported to the ICO further • Data Protection Officer
guidance can be found at [Link]

Where a decision to notify the ICO has been made the following must be included
as a minimum:
• Describe the nature of the personal Data Breach including where possible, the
categories and approximate number of data subjects and personal data records
concerned. • Information Security Manager
• Communicate the name and contact details of the contact point where more • CIRT
information can be obtained. • Data Protection Officer
• Describe the likely consequences of the personal Data Breach.
Describe the measures taken or proposed to be taken to address the personal Data
Breach, including, where appropriate, measures to mitigate its possible adverse
effects.

Data Loss Playbook OFFICIAL 15


Consider other Reporting requirements such as Reporting as a crime to Police
Scotland or to Regulators or Competent Authorities where relevant

Activity Description Stakeholders

Activities may include, but are not limited to:

• Information Security Manager


Incorporate technical and business analysis to develop a prioritised remediation • Core IT CIRT
Develop a plan. • CIRT
remediation plan
• Information Security Manager
Implement a communications strategy in line with the remediation plan. • Core IT CIRT
• CIRT

Data Loss Playbook OFFICIAL 16


5. Remediation – Contain, Eradicate and Recover
Remediation Phase
The remediation phase has the following objectives:

Phase objectives • Contain the technical mechanism of the Data Breach;


• Eradicate the technical mechanism of the Data Breach;
• Recover affected systems and services back to a Business As Usual (BAU) state.

Activity Description Stakeholders


Contain the technical mechanisms of the Data Breach, including:

Isolate all affected systems or accounts from the infrastructure through removal
• Information Security Manager
from the network or application of strict access controls, to prevent further data
• Core IT CIRT
exfiltration.

• Information Security Manager


Implement rules to block detected suspicious traffic leaving the network.
• Core IT CIRT
Containment • Information Security Manager
Secure copies of infected systems and malware for further investigation, if not
already completed. • Core IT CIRT

Reverse engineer malware to identify the indicators of compromise that will assist • Information Security Manager
with eradication phase. • Core IT CIRT

• Information Security Manager


Safeguard critical assets to prevent further harm or theft of data.
• Core IT CIRT

Data Loss Playbook OFFICIAL 17


• Information Security Manager
Remotely erase any lost or stolen assets where possible.
• Core IT CIRT

Reset passwords of legitimate user accounts and reduce permissions where • Information Security Manager
possible. • Core IT CIRT

• Information Security Manager


Isolate unauthorised user accounts and analyse any remove data stored.
• Core IT CIRT

Contain the business effects of the cyber incidents:

• Information Security Manager


Implement the notification strategy including any internal or external notifications,
• Core IT CIRT
the notification of employees, third parties, service providers and customers.
• CIRT

• Information Security Manager


Support the development of external communications by providing accurate,
• CIRT
simple lines to take, in line with technical remediation activities.
• Comms

• Information Security Manager


Engage the Data Protection Authority in the country where the compromise took • CIRT
place, if appropriate. • Data Protection Officer
• Legal Services

Activity Description Stakeholders

Activities may include, but are not limited to:

Eradication
• Information Security Manager
Remove any malware identified during the analysis phase using appropriate tools.
• Core IT CIRT

Data Loss Playbook OFFICIAL 18


Remove any identified artefacts used to facilitate the breach, such as scripts, code • Information Security Manager
and binaries. • Core IT CIRT

Disable system and user accounts that have been used as a platform to conduct • Information Security Manager
the attack. • Core IT CIRT

• Information Security Manager


Identify common removal methods from trusted sources (AV providers).
• Core IT CIRT

Complete an automated or manual removal process of the malware using • Information Security Manager
appropriate tools. • Core IT CIRT

• Information Security Manager


Conduct a restoration of affected networked systems from a trusted back up.
• Core IT CIRT

Re-install any standalone systems from a clean OS back-up before updating with • Information Security Manager
trusted data back-ups. • Core IT CIRT

• Information Security Manager


Change any compromised account details.
• Core IT CIRT

• Information Security Manager


Confirm policy compliance across the estate. • Core IT CIRT
• CIRT

Activity Description Stakeholders


Activities may include, but are not limited to:

Data Loss Playbook OFFICIAL 19


• Information Security Manager
Recover systems based on business impact analysis and business criticality. • Core IT CIRT
• CIRT

• Information Security Manager


Complete AV and advanced malware scanning of all systems, across the estate.
• Core IT CIRT

• Information Security Manager


Re-set the credentials of all involved system(s) and users account details.
• Core IT CIRT

• Information Security Manager


Reintegrate previously compromised systems.
• Core IT CIRT
Recover to BAU • Information Security Manager
Restore any corrupted or destroyed data.
• Core IT CIRT

• Information Security Manager


Restore any suspended services.
• Core IT CIRT

• Information Security Manager


Establish monitoring to detect further suspicious activity. • CIRT
• SIEM Provider

Co-ordinate the implementation of any necessary patches or vulnerability • Information Security Manager
remediation activities. • Core IT CIRT

Activity Description Stakeholders

Establish a Data Leak and Recovery Plan. This plan should state the • Information Security Manager
Data Recovery • Senior/ Gold Command Team
circumstances in which the organisation would engage with any Threat Actor
and Analysis
claiming to have exfiltrated data and define the general process for monitoring,

Data Loss Playbook OFFICIAL 20


accessing, reviewing, assessing data published on a Threat Actor Data Leak site.
His identifying arrangements for any ransom payment considerations ( Chief Exec
sign off) Activities may include, but are not limited to:

• Consider monitor Data Leak sites ( likely requiring a Dark Web capability)
• potentially seek proof of exfiltration
• consider engage Threat Actor as a delaying tactic with support of Law
Enforcement and or CIR
• identifying who and how often leak sites are monitored for publication
• identifying who, how and when leaked data will be recovered
• identifying who, how, where and when recovered data will be assessed on
the basis of sensitivity
• consider the notification process to data owners and individuals impacted
directly in the data leaks /compromise
• liaising with Police Scotland on preventative advice for data loss victims
• consider media handling

Data Loss Playbook OFFICIAL 21


6. Post Incident
Post-Incident Activities Phase
The post-incident activities phase has the following objectives:
• Complete an incident report including all incident details and activities;
Phase objectives
• Complete the lessons identified and problem management process;
• Publish appropriate internal and external communications.

Activity Description Stakeholders

Draft a post-incident report that includes the following details as a minimum: • Senior Stakeholders
• Head of Information
• Details of the cause, impact and actions taken to mitigate the cyber incidents, Governance
and including, timings, type and location of incident as well as the effect on
• Head of IT
users;
• Audit Committee
Incident reporting • Activities that were undertaken by relevant resolver groups, service providers
• Information Security Manager
and business stakeholders that enabled normal business operations to be
resumed; • Resilience Lead
• Recommendations where any aspects of people, process or technology could • Business Continuity Lead
be improved across the organisation to help prevent a similar cyber incidents • Police Lead
from reoccurring, as part of a formalised lessons identified process.

Complete the formal lessons identified process to feedback into future preparation • Information Security Manager
activities. • CIRT

Lessons
Identified & • Information Security Manager
Problem Conduct root cause analysis to identify and remediate underlying vulnerabilities. • Core IT CIRT
Management • CIRT

Consider sharing lessons identified with the wider stakeholders. • Information Security Manager

Data Loss Playbook OFFICIAL 22


• CIRT
• Resilience Lead
• Business Continuity Lead
• Policy Lead

Review staff welfare; working hours, over time, time off in lieu (TOIL) and • Information Security Manager
Human • HR
Resources expenses.

Activities may include, but are not limited to:

• Information Security Manager


Publish internal communications to inform and educate employees on Data Breach
• CIRT
attacks and security awareness.
• Communications

• Head of IT
Communications • Information Security Manager
Publish external communications, if appropriate, in line with the communications
strategy to provide advice to customers, engage with the market, and inform press • Communications Team
of the cyber incidents. • Resilience Lead
• Business Continuity Lead
These communications should provide key information of the cyber incidents
• Policy Lead
without leaving the organisation vulnerable or inciting further Data Loss attacks.

Data Loss Playbook OFFICIAL 23


7. Annex A: Flow Diagram
Data Loss Playbook
Prepare

Review threat Ensure access to CIRP, Maintain awareness


Review recent cyber
Review and intelligence feeds, Data Flow Diagrams with employees
Prepare incidents and
rehearse CIRP latest vulnerabilities and appropriate through security
outputs
and risks documentation awareness training

Notification through:
Reports of Data • Reports of customer or personal Collate initial
Detect

Escalate in Consider mobilising


Breach or data published online incident data and
Mobilise the CIRT accordance with the forensic readiness
compromise to • Data loss prevention logs and alerts classify cyber
CIRP capability
Service Desk • Reports of lost or stolen paperwork incident
or data

Scope the attack:


Confirm data involved is: Analyse the data Analyse the data types and
• What is the classification of the lost
• Legitimate types and quantities quantities to determine if there
Analyse

or compromised data?
• Current to determine if has been a breach of financial Consider engaging
Engage technical • What is the impact to the
• Originates from the there has been a data (e.g. organisational financial the DPO and
staff organisation?
organisation or privacy breach (i.e. reports, customer or employee reporting to the ICO
• Are customers affected?
customer involving personal credit card details, bank details
• What legal and regulatory
data). etc.).
requirements have been violated?
Remediation

Contain systems
Consider Deploy latest
that have been Contain business effects Re-image systems
disconnecting malware definitions Restore serviced to
affected to prevent of the cyber security and scan for
infected systems to anti-malware BAU
further data incident malware
from the network solutions
exfiltration
Post Incident

Complete formal Publish internal Updates to cyber


Draft post-incident lessons learnt communications to incident
End
report process defined in educate employees on documentation
CIRP data security where required

Data Loss Playbook OFFICIAL 24

You might also like