Corporate Compliance

Q: What's the most critical information to include in a security incident-response plan?

Compliance Monitor, August 13, 2004

Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!

This varies depending on the complexity of your information systems and size of your organization. At a minimum, you should have the following:

  • Overview of the purpose and scope of the plan.
  • List of security incident-response team members and full contact information (e.g., cell and home phone numbers, personal e-mail address, personal instant messaging ID, pager, etc.).
  • List of the types of incidents that will cause you to invoke the plan.
  • Technologies in place to detect and respond to incidents.
  • Specific steps on how the team will respond to, contain, investigate, and recover from incidents.
  • Procedures for communicating with external entities such as patients, business associates, and the media. These practices are often overlooked, but are often the first actions you must take.
  • Procedures for testing the plan.
  • Procedures for keeping records associated with security incidents.

    This question was answered by Kevin Beaver, CISSP, founder and principal consultant of Principle Logic, LLC.



  • Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!

      Strategies for Health Care Compliance
    • Strategies for Health Care Compliance

      News and real-life examples to increase the effectiveness of your compliance program. Strategies for Health Care Compliance...

    • Compliance Monitor

      This HTML e-mail newsletter delivers news on Medicare and Medicaid fraud and abuse, as well as recent documents and targets...

    • Medicare Weekly Update

      Each issue of Medicare Weekly Update includes the latest CMS proposed and final rules, CMS manual revisions, and...

    • Medicare Update for Physician Services

      Medicare Update for Physician Services is a free, monthly e-zine that delivers news and information to help physician...

    Most Popular

    Related Articles